← Incident database

metabase-2026 · Disclosed 2026-08-06

Metabase: zero-day and administrator-session abuse

Metabase investigated abnormal API-key activity on August 3 and confirmed zero-day exploitation. Input handling and ORM behavior enabled administrator sessions and data access.

Zero-dayImplementationCVE-2026-72898

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Extra input keys, password-reset handling, and ORM acceptance of SQL expressions formed the exploit chain.

    [s1]Technical root cause
  • Reported fact

    Metabase confirmed compromise of fewer than 3% of cloud customers and some publicly exposed self-hosted installations.

    [s1]Scope of impact
  • Assessment

    The developer assesses advanced LLM involvement based on code-path complexity and User-Agent evidence.

    [s1]Was this AI?
  • Reported fact

    The vendor advisory identifies unauthenticated SQL injection enabling administrator access as CVE-2026-72898.

    [s3]Summary / CVE ID

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Metabase reported cloud fixes, patched self-hosted releases, and hardened input and SQL-expression handling.

    [s1]Remediation

Evidence relevant to prevention

Exploited before disclosure

Exploitation preceded disclosure. Inspect BI exposure, API keys, and data privileges; inspect input allowlists and SQL-expression boundaries in owned code.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementAssessment

The developer infers LLM involvement without confirming the attacker’s model or actual usage.

AI attribution is the developer’s assessment; total self-hosted impact and individual intrusion starts are unknown.

Sources

  1. [s1] Metabase · Primary source

    Vulnerability: what happened ↗

    Published 2026-08-27 · Reviewed 2026-10-02

  2. [s2] Metabase · Primary source

    Security update, 6 Aug 2026 ↗

    Published 2026-08-06 · Reviewed 2026-10-02

  3. [s3] Metabase · Primary source

    SQL injection using an unauthenticated endpoint leading to admin access ↗

    Published 2026-08-06 · Reviewed 2026-10-02