Metabase Discloses 10/10 Zero-Day SQL Flaw Exposing Data in 1.58+ Instances
Updated
Updated · InfoWorld · Aug 12
Metabase Discloses 10/10 Zero-Day SQL Flaw Exposing Data in 1.58+ Instances
3 articles · Updated · InfoWorld · Aug 12
Summary
CVE-2026-72898, disclosed Aug. 6, lets attackers gain raw SQL access to Metabase databases through the /api/session/reset_password endpoint, potentially exposing credentials, tokens, API keys and other sensitive data.
Metabase said it blocked the exploited endpoint, patched cloud customers, terminated relevant sessions and revoked credentials, but self-hosted deployments remain at risk until upgraded or the endpoint is blocked.
2,500 Metabase instances are visible on Shodan, and Wiz said 13% of cloud environments run self-hosted Metabase; about 25% of those are fully internet-accessible, widening the attack surface.
Kilo Code, Tally, Framework, n8n and ChecklyHQ said attackers accessed data such as usernames, email addresses, cloud passwords and Slack tokens, prompting password resets, key rotation and admin-account reviews.
Metabase said likely compromise shows as a POST reset_password call returning 400 followed by GET /api/user/current with 200, and urged customers to patch immediately, rotate connected-database credentials and audit logs for new admin accounts.
Could a hidden analytics tool embedded in your software be silently leaking your company's most sensitive database credentials right now?
How can organizations defend against critical zero-day exploits when they don't even realize they are running the compromised software?
Are traditional business intelligence architectures fundamentally broken by requiring omnipotent, continuous access to highly sensitive production data warehouses?