August 2026 Security Vulnerability: What happened?
Blog post from Metabase
Metabase disclosed a zero-day vulnerability discovered after a Cloud customer reported an API key created outside normal hours on August 3, 2026, with investigation finding that a single IP had used a similar attack sequence against multiple instances. The flaw affected installations running version 0.58 or later and resulted in compromise of fewer than 3% of Metabase Cloud customers before mitigation, along with some publicly accessible open-source and self-hosted deployments. The chained vulnerability began at the password-reset endpoint, where permissive schema validation allowed extra fields, a prior authentication refactor forwarded the full request body, and interactions between the Toucan2 ORM and HoneySQL enabled raw SQL injection through a supplied user ID. Attackers could use this access to create sessions for the initial administrator account, inspect data, and create API keys for bulk downloads. Metabase blocked the originating network activity, deployed Cloud patches, released patched versions on August 6, engaged an external incident-response firm, and added fixes for related vulnerabilities. The company also introduced broader hardening measures, beginning with version 63.13, including stricter validation, protections against SQL injection and session creation, improved permission and cache isolation, and defenses involving query processing, SSRF, sandboxes, and database connection impersonation.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.