Critical Metabase SQL Injection Flaw Exploited to Steal Admin Access and Database Data
A critical unauthenticated SQL injection vulnerability (CVSS 10.0) in Metabase versions 0.58 through 0.63 has been actively exploited since at least August 3, 2026, allowing attackers to gain administrator privileges without any login credentials. Threat actors exploit the public password reset API endpoint to inject SQL, escalate to admin access, and then extract connected database credentials and data. Companies including Framework and Tally confirmed unauthorized access, with Framework reporting theft of customer names, emails, billing addresses, and phone numbers, while Tally had email addresses and password hashes exposed. Metabase Cloud has already been patched automatically, but administrators of self-hosted instances must manually update to minimum safe versions such as 0.58.24, 0.59.21, or 0.63.5 depending on their release branch. Recommended mitigations include updating immediately, blocking the reset-password endpoint, restricting source IPs, and applying least-privilege principles to connected database credentials.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in