{"id":9103,"date":"2026-08-12T02:40:58","date_gmt":"2026-08-12T02:40:58","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9103"},"modified":"2026-08-12T02:40:58","modified_gmt":"2026-08-12T02:40:58","slug":"metabase-sqli-exploit-grants-attackers-total-access","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9103","title":{"rendered":"Metabase SQLi exploit grants attackers total access"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers\u2019 sensitive credentials, tokens, API keys, and other data may have been exposed.<\/p>\n<p class=\"wp-block-paragraph\">The Metabase vulnerability revealed on August 6, designated <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-72898\" target=\"_blank\" rel=\"noopener\">CVE-2026-72898<\/a>, is identified as critical, with a severity score of 10, the highest possible rating. It is present in versions 1.58 and up.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou don\u2019t see a perfect 10\/10 on CVSS often, but when you do, be worried,\u201d noted <a href=\"https:\/\/www.linkedin.com\/in\/dbshipley\/\" target=\"_blank\" rel=\"noopener\">David Shipley<\/a>, CEO of Beauceron Security. SQL injection is \u201cold school and painful, as there\u2019s now working proof of concept exploit code.\u201d<\/p>\n<h2 class=\"wp-block-heading\">\u2018Unmitigated, raw\u2019 database access<\/h2>\n<p class=\"wp-block-paragraph\">Metabase is an open-source BI tool that customers can connect to popular databases, including Databricks, MongoDB, Oracle, Snowflake, Amazon, BigQuery, and many others. They can use the platform to access analytics, query and visualize data, and build dashboards, among other actions.<\/p>\n<p class=\"wp-block-paragraph\">Search engine Shodan has tracked roughly 2,500 Metabase instances, and security company Wiz <a href=\"https:\/\/www.wiz.io\/blog\/inside-the-metabase-sqli-exploited-in-the-wild\">reported that<\/a> around 13% of cloud environments have deployed self-hosted Metabase instances; of those, about 25% are fully accessible on the internet.<\/p>\n<p class=\"wp-block-paragraph\">According to Metabase\u2019s disclosure, a threat actor used a zero-day SQL injection vulnerability in the company\u2019s platform to gain access. The entry point is <em>\/api\/session\/reset_password<\/em>.<\/p>\n<p class=\"wp-block-paragraph\">Metabase said that after it discovered the attack, it immediately blocked the exploited endpoints, patched the vulnerability, terminated relevant sessions, and revoked credentials used in the incident. Metabase Cloud customers have already been upgraded and patched against the vulnerability, but self-hosted Metabase customers may still be vulnerable unless they have patched.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis vulnerability allows attackers to have unmitigated, raw SQL access to the Metabase database,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/scottmiserendino\" target=\"_blank\" rel=\"noopener\">Scott Miserendino<\/a>, CTO at DataBee. They can steal or alter account credentials for connected databases, create new administrator accounts, change app configurations, escalate privileges, or even \u201cdegrade, alter or destroy\u201d information.<\/p>\n<p class=\"wp-block-paragraph\">He emphasized that this vulnerability can also affect platforms that use original equipment manufacturer (OEM) versions of \u00a0Metabase as part of their infrastructure. This means affected users may not even know they are affected, because they are not aware that Metabase is part of the product they purchased.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt is a very serious vulnerability,\u201d Miserendino cautioned.<\/p>\n<h2 class=\"wp-block-heading\">Victims so far<\/h2>\n<p class=\"wp-block-paragraph\">Companies that have been impacted by the breach seem, at least to so far, to be smaller organizations and startups. They include <a href=\"https:\/\/www.anaconda.com\/blog\/metabase-incident-impacting-kilo-code-data\" target=\"_blank\" rel=\"noopener\">Kilo Code<\/a>, which was recently acquired by Anaconda; Y Combinator backed <a href=\"https:\/\/news.ycombinator.com\/item?id=49213500\" target=\"_blank\" rel=\"noopener\">Tally<\/a>, which is building autonomous accounting agents; personal computer manufacturer <a href=\"https:\/\/community.frame.work\/t\/framework-data-breach-discussion\/83939\" target=\"_blank\" rel=\"noopener\">Framework<\/a>; workflow automation platform <a href=\"https:\/\/blog.n8n.io\/metabase-security-incident-update\/\" target=\"_blank\" rel=\"noopener\">n8n<\/a>; and AI testing and monitoring platform provider <a href=\"https:\/\/www.checklyhq.com\/blog\/metabase-security-incident\/\" target=\"_blank\" rel=\"noopener\">ChecklyHQ<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The impacted companies report that <a href=\"https:\/\/www.csoonline.com\/article\/4205861\/evidence-points-to-cybercriminals-stepping-up-their-ai-game.html\" target=\"_blank\" rel=\"noopener\">threat actors<\/a> accessed records containing usernames, email addresses, cloud passwords, cryptographic hashes of OpenTelemetry (OTel) API keys used for trace collection, Slack access tokens, and other sensitive information.<\/p>\n<p class=\"wp-block-paragraph\">They all report that they are directly contacting impacted customers and have taken mitigation actions, including rotating potentially impacted credentials and API keys, resetting all user passwords, invalidating all Slackbot authentication tokens for impacted users, removing compromised admin accounts, and reviewing internal audit logs.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe vulnerability was in a vendor\u2019s product, but protecting your data is our job, and this incident put some of it at risk,\u201d Checkly said in its notice.<\/p>\n<p class=\"wp-block-paragraph\">It said it is rethinking internal processes around analytics tools, improving sanitation when storing check configurations and data, and performing extensive audits to limit exposure. Its on-call engineers will also be paged when future vendor security notices are released to allow for faster response.<\/p>\n<p class=\"wp-block-paragraph\">\u201cRotating credentials fixes the immediate problem,\u201d the company noted. \u201cIt does not fix the reason this hurt: Our analytics environment held more sensitive data and had broader access than it needed.\u201d<\/p>\n<h2 class=\"wp-block-heading\">What affected customers should do<\/h2>\n<p class=\"wp-block-paragraph\">The attack pattern, according to Metabase, is:<\/p>\n<p>A call to <em>POST \/api\/session\/reset_password<\/em> with a 400 status code<\/p>\n<p>This is followed by a call to <em>GET \/api\/user\/current<\/em> with a 200 status code<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you find that pattern in your application logs or in your Metabase server ingress logs, it is likely that your instance has been compromised,\u201d the company said.<\/p>\n<p class=\"wp-block-paragraph\">Customers should upgrade to an appropriate patch as soon as possible. For instance, if running Metabase 0.58.6, move to 0.58.24 or later. Those unable to immediately upgrade can implement a temporary workaround by blocking the <em>\/api\/session\/reset_password<\/em> endpoint.<\/p>\n<p class=\"wp-block-paragraph\">If the <em>\/api\/session\/reset_password<\/em> endpoint of a Metabase instance is publicly accessible, enterprises should revoke all active user sessions; review and delete any unrecognized API keys; audit data warehouse logs and admin accounts for unauthorized access or other unexpected changes; rotate credentials for all connected databases; and review Metabase activity and query histories.<\/p>\n<p class=\"wp-block-paragraph\">If wrapping a third-party\u2019s REST interface, enterprises should always perform their own SQLi detection, DataBee\u2019s Miserendino advised. This can be done by incorporating a web access firewall (WAF) or reverse proxy.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEnterprises should also monitor their security and database logs for the creation of new or recently elevated administrator accounts,\u201d he said, \u201cor other unusual activity such as large volumes of data drops.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Anaconda, for its part, urges customers to remain diligent: \u201cBe on alert for phishing\/social engineering, and maintain credential hygiene (including auditing, reviewing, and rotating credentials regularly) and spam monitoring.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers\u2019 sensitive credentials, tokens, API keys, and other data may have been exposed. The Metabase vulnerability revealed on August 6, designated CVE-2026-72898, is identified as critical, with a severity score of 10, the highest possible rating. It is present in [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9104,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9103","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9103"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9103"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9103\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9104"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}