Critical SQL Injection Zero-Day in Metabase Leads to Data Breach

Critical SQL Injection Zero-Day in Metabase Leads to Data Breach

First seen 7 Aug 2026, 21:12 UTC MetabaseBleepingcomputer 71% similarity 80.0

Article Content

Browse articles
ThreatCluster

A critical SQL injection vulnerability in Metabase versions 1.58 and above was exploited in zero-day attacks, compromising customer data. The vulnerability allows unauthenticated remote attackers to gain administrator access to Metabase instances, enabling them to alter configurations, steal credentials, and export data. Metabase has confirmed active exploitation of this flaw, which has not yet been assigned a CVE identifier but is rated Critical with a CVSS score of 10.0. Both Metabase Cloud and self-hosted installations are affected, with the company urging immediate upgrades for self-hosted users. Framework, a laptop manufacturer, reported that customer information was stolen due to this breach. Metabase has rolled out patches for Cloud customers and provided guidance for self-hosted users to mitigate the risk.

Key Points: • A critical SQL injection vulnerability in Metabase allows unauthorized access to customer data. • The flaw affects versions 1.58 and above, with active exploitation confirmed. • Metabase recommends immediate upgrades and has provided specific steps for self-hosted users.

ThreatCluster AI How this analysis works

Timeline

2026-08-07
Metabase identifies zero-day vulnerability
Metabase disclosed a critical SQL injection vulnerability affecting versions 1.58 and above, exploited in attacks against customer instances.
Bleepingcomputer
2026-08-07
Metabase Cloud patched
Metabase confirmed that its Cloud customers have been upgraded and patched against the vulnerability.
Metabase
2026-08-07
Framework confirms data breach
Framework reported that customer information was stolen after attackers compromised its Metabase instance.
Bleepingcomputer

Community

Browse all →