The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 07:08 pm AEST · 9 August 2026

42 DAYS AGO Key event Share

Metabase zero-day SQL injection flaw actively exploited in customer data thefts

Metabase zero-day SQL injection flaw actively exploited in customer data thefts
Photograph: BleepingComputer

A critical SQL injection vulnerability in Metabase versions 1.58 and above has been actively exploited to breach customer instances and steal data, Metabase disclosed on Thursday. The unauthenticated flaw gives attackers administrator access to instances, allowing them to steal credentials, read databases and export data. Metabase Cloud customers have been patched; self-hosted users must upgrade immediately to versions 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5.

Laptop maker Framework confirmed attackers used the vulnerability to steal customer names, email addresses, billing and shipping addresses, phone numbers and login IP addresses. The flaw carries a CVSS score of 10.0 and has not yet been assigned a CVE identifier. Metabase advises customers to revoke user sessions, rotate database credentials, and review logs for POST requests to /api/session/reset_password followed by GET requests to /api/user/current, which indicate compromise, Mayank Parmar reports for BleepingComputer.

Metabase SQLi zero-day exploited in customer data-theft attacks A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. bleepingcomputer.com
cybersecuritydata-breachvulnerability

Follow the live coverage →

Metabase zero-day SQL injection flaw actively exploited in customer data thefts | The Financial Register Inward Money