Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

How widespread is the recent Metabase SQL injection attack?

0
Medium
Vulnerabilitycybersecurityreddit
Published: 08/17/2026 (08/17/2026, 00:45:55 UTC)
Source: Reddit Cybersecurity

Description

A zero-day SQL Injection vulnerability (CVE-2026-72898) was disclosed in the Metabase platform on August 6, 2026. The flaw exists in the /api/session/reset_password endpoint, allowing injection via an unexpected user-id parameter in the JSON body. The vulnerability affects versions starting from 1.58 due to a refactor in the auth_identity module. Exploitation has been observed in the wild, with proof-of-concept exploits publicly available. Self-hosted Metabase instances are at risk and should be patched immediately. The patch validates the user-id as a positive integer, preventing injection. The vulnerability impacts multiple database backends supported by Metabase. Organizations with internet-facing Metabase instances should urgently verify and remediate exposure.

Reddit Discussion

r/cybersecurity·posted by u/Razin_misab
00

I recently led an incident response investigation for a FinTech client involving the exploitation of Metabase, and the impact was significant.

With the recent reports of active exploitation, I'm curious to understand how widespread this is across the security community.

For those working with Metabase:

Has your organization been affected or received a security notification?

Was your Metabase instance internet-facing?

Have you identified exploitation attempts or unauthorized access?

Were you able to patch before exploitation?

Have you observed any data exposure or compromise?

I’m particularly interested in hearing from security teams and Metabase administrators about how many organizations have been affected or potentially exposed.

https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild

If you've investigated a related incident, what did you observe?

Affected software

Affected versions
>=1.58 <1.58.24

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 00:56:11 UTC

Technical Analysis

On August 6, 2026, Metabase disclosed a zero-day SQL Injection vulnerability identified as CVE-2026-72898 affecting the /api/session/reset_password API endpoint. The vulnerability arises because the API merges incoming JSON request data with authentication results without stripping unexpected keys, allowing an attacker to supply a crafted user-id parameter containing a HoneySQL :raw directive that injects arbitrary SQL. The flaw was introduced in version 1.58 during a refactor of the auth_identity module. The patch, available in versions after 1.58, adds validation to ensure user-id is a positive integer before use in SQL queries. Exploitation has been observed in the wild, with public proof-of-concept code released. Approximately 13% of cloud environments have self-hosted Metabase, with 25% of those instances internet accessible, increasing exposure risk. The vulnerability affects multiple database backends including H2, PostgreSQL, MySQL, and MariaDB. Organizations running vulnerable versions should patch immediately and investigate potential exploitation.

Potential Impact

The vulnerability allows an attacker to perform blind SQL Injection on the Metabase platform via the reset_password API endpoint, potentially leading to unauthorized data access or manipulation. Given the injection occurs in a critical authentication-related API, exploitation could compromise user accounts or expose sensitive data. The vulnerability affects self-hosted Metabase instances starting from version 1.58. Public proof-of-concept exploits and observed in-the-wild exploitation increase the risk. Approximately 25% of self-hosted instances are internet-facing, elevating exposure. The impact is significant for organizations using vulnerable versions without patching, especially those with internet-accessible deployments.

Mitigation Recommendations

A patch fixing this vulnerability is available in Metabase versions after 1.58. Organizations should immediately upgrade to a fixed version (at least 1.58.24 or later) to remediate the issue. The patch validates the user-id parameter to prevent SQL Injection. Self-hosted Metabase instances must be patched as soon as possible. Users should review their /api/session/properties endpoint to identify vulnerable versions and investigate any suspicious activity related to the reset_password API. The vendor advisory and Wiz Threat Intel Center provide detailed remediation and detection guidance. No indication exists that the vulnerability is mitigated without patching. There is no mention of cloud service remediation, so self-hosted instances require manual patching.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":22,"reasons":["external_link","non_newsworthy_keywords:meta","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":["meta"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a825c24bf8831d539f0beac

Added to database: 08/17/2026, 00:56:04 UTC

Last enriched: 08/17/2026, 00:56:11 UTC

Last updated: 08/17/2026, 02:11:00 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses