• News/
  • bleepingcomputer-20260807201446

Metabase SQLi zero-day exploited in customer data-theft attacks

BleepingComputer
·
Mayank Parmar
·
Published Aug 7, 2026
·
Updated

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. Metabase disclosed the attacks on Thursday, warning that its Metabase Cloud SaaS platform was compromised through a previously unknown vulnerability affecting versions 1.58 and above. The company warns that self-hosted installations are also vulnerable. "We recently identified that Metabase Cloud was attacked by someone utilizing an unknown ("0-day") security vulnerability in versions 1.58 and above," Metabase CEO Sameer Al-Sakran warned in a blog post. Metabase confirmed it blocked the endpoints used for the attack and immediately rolled out a fix for the vulnerability. "The vulnerability is an unauthenticated SQL injection flaw in Metabase that can ultimately give a remote attacker administrator access to a customer's instance." While Metabase has not assigned the vulnerability a CVE identifier, its security advisory rates it as Critical with a CVSS score of 10.0 and confirms that it has been actively exploited. "This is a CRITICAL vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance," reads an associated security advisory. "From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through ...

Read full article

Affected Software

2 affected components
Metabase Metabase
Metabase Metabase>=0.58<=0.63

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical SQL injection vulnerability in Metabase that has been exploited in attacks targeting customer data.

2

What security implications are discussed in the article?

The article warns that customer instances have been breached, resulting in data theft due to an exploited zero-day vulnerability in Metabase.

3

What products or software are affected by the vulnerability?

The vulnerability primarily affects the Metabase Cloud SaaS platform, with specific impact on customer instances of Framework and Tally.

4

When was the zero-day vulnerability disclosed?

The zero-day vulnerability was disclosed by Metabase on August 7, 2026.

5

Is the vulnerability part of any known vulnerability catalog?

Yes, the exploitation of this vulnerability is listed in the Known Exploited Vulnerabilities (KEV) catalog, with a listing date of August 8, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203