www.securityweek.com 8/10/2026, 11:20:52 AM · external

Metabase patches critical SQL injection zero day flaw

Metabase patches critical SQL injection zero day flaw
CyberSIXT Evidence Panel
Primary Source metabase.com

METABASE has issued urgent patches for a critical SQL injection vulnerability exploited as a zero-day attack. This vulnerability allows unauthorized attackers to execute SQL queries, potentially compromising application configuration, credentials, and data. No CVE identifier is assigned yet. Metabase has addressed the issue in its Cloud instances and recommends users apply patches promptly to avoid exposure. A temporary workaround is to block specific API endpoints.

Users are advised to monitor access logs for indicators of compromise, particularly specific API calls that may signal exploitation. Affected versions include 63.5, 62.9, 61.11, 60.17, 59.21, and 58.24.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline