Home / Companies / Metabase / Blog / August 2026

August 2026 Summaries

1 posts from Metabase

Filter
Month: Year:
Post Summaries Back to Blog
Metabase disclosed a security incident involving a previously unknown vulnerability affecting self-hosted versions 0.58 and later, which allowed attackers to exploit the public password-reset endpoint, inject arbitrary SQL into the application database, and potentially obtain administrator access. Such access could enable configuration changes, theft of stored database credentials, access to connected data, and data exports. Metabase Cloud instances have already been patched, while self-hosted users are urged to upgrade immediately to the latest safe point release for their major version, with versions earlier than 0.58 unaffected. Organizations whose password-reset endpoint was publicly accessible should revoke user sessions, inspect API keys and administrator accounts, rotate connected-database credentials, and review warehouse, activity, and query logs for suspicious activity. A likely compromise is indicated by a failed POST request to the password-reset endpoint followed by a successful GET request to the current-user endpoint, and users unable to upgrade promptly are advised to temporarily block the affected endpoint.
Aug 06, 2026 499 words in the original blog post.