Overview
- Metabase detected active exploitation of an unauthenticated SQL injection on August 3 that let remote attackers inject arbitrary SQL and gain administrator access to customer instances.
- The company blocked the abused endpoint in its Cloud service and rolled out patched point releases so Metabase Cloud customers were upgraded automatically.
- Metabase published an indicator of compromise—POST /api/session/reset_password returning 400 followed by GET /api/user/current returning 200—and released fixed minimum point versions for each affected branch.
- At least two customers, Framework and Tally, confirmed that attackers exfiltrated customer data such as names, emails and login IPs or password hashes while other customers like LexisNexis are still investigating impact.
- Metabase urges self-hosted operators to apply the exact patched point release now or temporarily block /api/session/reset_password, revoke sessions, audit API keys and admin accounts, rotate database credentials, and review logs for the IoC pattern.