logo

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

ID: cd3dee73-39b5-5435-b714-d9f7da507c79

STIX ID: report--cd3dee73-39b5-5435-b714-d9f7da507c79

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-08-10

Date Updated: 2026-08-11

Author: Rob Wright

...
...

A zero-day SQL injection in Metabase Cloud (affecting v1.58+) was exploited in the wild, giving attackers administrator access to instances, the ability to change configuration, steal stored database credentials, read and export connected data, and impact downstream organizations. Metabase patched and auto-upgraded Cloud instances but warned self-hosted customers to upgrade or block the /api/session/reset_password endpoint; several companies (n8n, Kilo) disclosed customer data exposure as a result.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.