Metabase zero-day exploited to access Framework customer data – Help Net Security

August 10, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: helpnetsecurity.com

Threat Risk: High
Victim: Companies using Metabase BI services
Incident: Exploitation of a zero-day SQL injection vulnerability in Metabase resulting in unauthorized access to customer data.
Impact: Exfiltration of customer PII, password hashes, and Slack access tokens across multiple organizations.
Attacker: Unidentified threat actors
Analysis: Attackers leveraged an unauthenticated SQL injection vulnerability in Metabase versions 58 and above to gain administrative control over cloud instances. This access allowed the theft of database credentials and the subsequent exfiltration of customer PII and API tokens. The attack pattern is identifiable via specific API request sequences in server logs.
Recommendations: Update Metabase instances to the latest patched version immediately.; Rotate all database credentials and API keys connected to Metabase.; Monitor server logs for a 400 error on /api/session/reset_password followed by a 200 on /api/user/current.
Source: Help Net Security

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *