logo

Inside the Metabase SQLi: Exploited in the Wild

ID: 1a8da9ec-ed2d-5ec2-af4e-f5524070ba30

STIX ID: report--1a8da9ec-ed2d-5ec2-af4e-f5524070ba30

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2026-08-10

Date Updated: 2026-08-19

Author: Rami McCarthy

...
...

Wiz Research analyzed a zero-day SQL injection in Metabase (CVE-2026-72898) disclosed 2026-08-06 that enables attacker-controlled HoneySQL :raw payloads via an unexpected "user-id" key in /api/session/reset_password; the flaw affects versions 1.58+ and has been observed exploited in the wild with public PoCs available, exposing self-hosted and cloud Metabase instances and prompting urgent patching and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.