www.darkreading.com 8/10/2026, 9:41:01 PM · external

Zero day SQL flaw in Metabase Cloud leaks customer data

Zero day SQL flaw in Metabase Cloud leaks customer data
CyberSIXT Evidence Panel
Primary Source metabase.com

A zero-day SQL-injection vulnerability in Metabase Cloud, affecting version 1.58 and above, has been exploited, potentially allowing unauthorized remote access to sensitive data of downstream organizations. Metabase has issued a patch for affected users but those with self-hosted instances and exposed endpoints remain at risk. The critical nature of the vulnerability is underscored by a maximum CVSS score of 10, enabling attackers to access application configurations and sensitive data.

Companies like n8n and Kilo Code have reported breaches involving customer records. Users are advised to upgrade to fixed versions and secure exposed API endpoints.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline