August 2026 Summaries
1 posts from Metabase
Filter
Month:
Year:
Post Summaries
Back to Blog
Metabase disclosed a security incident involving a previously unknown vulnerability affecting self-hosted versions 0.58 and later, which allowed attackers to exploit the public password-reset endpoint, inject arbitrary SQL into the application database, and potentially obtain administrator access. Such access could enable configuration changes, theft of stored database credentials, access to connected data, and data exports. Metabase Cloud instances have already been patched, while self-hosted users are urged to upgrade immediately to the latest safe point release for their major version, with versions earlier than 0.58 unaffected. Organizations whose password-reset endpoint was publicly accessible should revoke user sessions, inspect API keys and administrator accounts, rotate connected-database credentials, and review warehouse, activity, and query logs for suspicious activity. A likely compromise is indicated by a failed POST request to the password-reset endpoint followed by a successful GET request to the current-user endpoint, and users unable to upgrade promptly are advised to temporarily block the affected endpoint.
Aug 06, 2026
499 words in the original blog post.