Published Saturday, August 08, 2026 at 10:15 AM PT

BLUF: Metabase zero-day allowing unauthenticated remote admin access is exploited in the wild. Customer data theft confirmed. Immediate isolation and monitoring required; patch availability pending.
DETAILS
- SQL injection vulnerability in Metabase permits remote, unauthenticated attackers to achieve full administrative access without credentials
- Exploitation confirmed active in production environments; customer data exfiltration campaigns underway
- Vulnerability grants attackers ability to read/export analytics, user accounts, connected database credentials, and underlying data accessible via Metabase queries
- Reported by multiple independent sources (SecurityAffairs, The Hacker News, BleepingComputer) with consistent exploitation narrative
- Specific affected version range, CVE identifier, and patch timeline not yet disclosed in available reporting
IMPACT
- Scope: All Metabase deployments (cloud, on-premises) are potentially vulnerable until patched
- Access: Attackers gain admin-level control without authentication; no prior foothold required
- Data at risk: All analytics, credentials, and database access strings stored or queryable within Metabase; any exported datasets since deployment should be considered compromised
- Active threat: Exploitation is not hypothetical; customer environments have already been targeted
RECOMMENDED ACTIONS
- NOW: Restrict network access to Metabase to trusted IPs only; log and review all admin account activity for unauthorized additions
- Urgent: Check Metabase GitHub releases, security advisories, and official channels for patch; have deployment plan ready
- Interim: Isolate Metabase from production networks if operationally feasible; segregate any connected database credentials
- After patching: Audit for unauthorized admin accounts created during active exploitation window; rotate database credentials accessible through Metabase
- Treat all data exported from Metabase as potentially exposed to attackers
SOURCES
- SecurityAffairs: “Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data”
- The Hacker News: “Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication”
- BleepingComputer: “Metabase SQLi zero-day exploited in customer data-theft attacks”
Recent high-severity events at publish time:

