securityonline.info 8/8/2026, 8:50:52 AM · external

Metabase SQL Injection Zero-Day (CVSS 10) Exploited

Metabase SQL Injection Zero-Day (CVSS 10) Exploited
CyberSIXT Evidence Panel
Primary Source metabase.com
CISA KEV Listed in KEV
Patch Patch Available

A critical vulnerability (CVE-2026-8037) has been found in Metabase, a widely used open-source business intelligence tool, involving an unauthenticated SQL injection that allows attackers to gain full administrator access. The vulnerability is rated CVSS 10 and affects self-hosted instances running version 1.58 and above, with active exploitation confirmed in the wild. The flaw resides in a public endpoint that does not require login, enabling arbitrary SQL injection.

Users are advised to upgrade to the latest versions immediately or temporarily block the affected endpoint and revoke active sessions post-patching. Metabase Cloud instances have already been patched. Detection patterns for exploitation include specific API calls that return unusual HTTP status codes.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline