Metabase Patches Vulnerability Exploited as Zero-Day
A critical SQL injection vulnerability in Metabase allows unauthenticated remote attackers to gain administrative access. Exploited as a zero-day, the flaw enables attackers to execute arbitrary SQL queries, modify application configuration, steal stored database credentials, and access or export connected data. Metabase has released patches for multiple versions and updated its cloud instances. Users unable to patch immediately are advised to block a specific API endpoint as a temporary mitigation and perform post-incident remediation steps if compromise is suspected.
AI Analysis
Technical Summary
Metabase disclosed a critical-severity SQL injection vulnerability exploited in the wild as a zero-day that permits unauthenticated remote attackers to inject arbitrary SQL queries into the application database. This allows attackers to escalate privileges to administrative level, change application settings, steal credentials for connected databases, and access or export data accessible through those connections. The vulnerability was discovered following exploitation attempts targeting Metabase Cloud. Metabase promptly blocked attack endpoints, patched the vulnerability, and updated cloud instances. Self-hosted users are urged to apply patches for versions 58.24, 59.21, 60.17, 61.11, 62.9, and 63.5 or block the /api/session/reset_password endpoint as a temporary workaround. Indicators of compromise include specific API call patterns in logs. Additional recommended post-compromise actions include revoking active sessions, reviewing and deleting unrecognized API keys, auditing administrative accounts, rotating database credentials, and monitoring logs for suspicious activity.
Potential Impact
The vulnerability allows unauthenticated remote attackers to gain full administrative access to Metabase instances. This access enables attackers to alter application configurations, steal credentials for connected databases, and read or export any data accessible through those database connections. Such compromise can lead to significant data exposure and loss of control over the affected Metabase environment.
Mitigation Recommendations
Metabase has released official patches for versions 58.24, 59.21, 60.17, 61.11, 62.9, and 63.5 that address this vulnerability. Metabase Cloud instances have already been updated and patched by the vendor. Self-hosted users should apply these patches immediately. Where patching is not possible, users should block the /api/session/reset_password endpoint to mitigate risk temporarily. If compromise is suspected, users should revoke all active user sessions, review and delete unrecognized API keys, audit administrative accounts, rotate credentials for all connected databases, and review logs for suspicious activity, particularly the specified API call patterns.
Metabase Patches Vulnerability Exploited as Zero-Day
Description
A critical SQL injection vulnerability in Metabase allows unauthenticated remote attackers to gain administrative access. Exploited as a zero-day, the flaw enables attackers to execute arbitrary SQL queries, modify application configuration, steal stored database credentials, and access or export connected data. Metabase has released patches for multiple versions and updated its cloud instances. Users unable to patch immediately are advised to block a specific API endpoint as a temporary mitigation and perform post-incident remediation steps if compromise is suspected.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Metabase disclosed a critical-severity SQL injection vulnerability exploited in the wild as a zero-day that permits unauthenticated remote attackers to inject arbitrary SQL queries into the application database. This allows attackers to escalate privileges to administrative level, change application settings, steal credentials for connected databases, and access or export data accessible through those connections. The vulnerability was discovered following exploitation attempts targeting Metabase Cloud. Metabase promptly blocked attack endpoints, patched the vulnerability, and updated cloud instances. Self-hosted users are urged to apply patches for versions 58.24, 59.21, 60.17, 61.11, 62.9, and 63.5 or block the /api/session/reset_password endpoint as a temporary workaround. Indicators of compromise include specific API call patterns in logs. Additional recommended post-compromise actions include revoking active sessions, reviewing and deleting unrecognized API keys, auditing administrative accounts, rotating database credentials, and monitoring logs for suspicious activity.
Potential Impact
The vulnerability allows unauthenticated remote attackers to gain full administrative access to Metabase instances. This access enables attackers to alter application configurations, steal credentials for connected databases, and read or export any data accessible through those database connections. Such compromise can lead to significant data exposure and loss of control over the affected Metabase environment.
Mitigation Recommendations
Metabase has released official patches for versions 58.24, 59.21, 60.17, 61.11, 62.9, and 63.5 that address this vulnerability. Metabase Cloud instances have already been updated and patched by the vendor. Self-hosted users should apply these patches immediately. Where patching is not possible, users should block the /api/session/reset_password endpoint to mitigate risk temporarily. If compromise is suspected, users should revoke all active user sessions, review and delete unrecognized API keys, audit administrative accounts, rotate credentials for all connected databases, and review logs for suspicious activity, particularly the specified API call patterns.
Technical Details
- Classification
- {"confidence":0.73,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/metabase-patches-vulnerability-exploited-as-zero-day/","fetched":true,"fetchedAt":"2026-08-10T11:11:13.107Z","wordCount":997}
Threat ID: 6a79b1d1bf8831d53990a8a7
Added to database: 08/10/2026, 11:11:13 UTC
Last enriched: 08/10/2026, 11:11:27 UTC
Last updated: 08/10/2026, 16:19:04 UTC
Views: 35
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.