Metabase Zero-Day SQL Injection (GHSA-vwf4-m7j8-wcjf) Exploited In the Wild for Admin Access — Threadlinqs Intelligence
As of 2026-08-08, Metabase Zero-Day SQL Injection (GHSA-vwf4-m7j8-wcjf) Exploited In the Wild for Admin Access is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 9 indicators of compromise.
Threat ID: TL-2026-1946 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
An unauthenticated, CVSS 10.0 SQL injection zero-day in the Metabase business-intelligence platform (GHSA-vwf4-m7j8-wcjf), reachable through the unauthenticated POST /api/session/reset_password
On 2026-08-06 Metabase, Inc. published GitHub Security Advisory GHSA-vwf4-m7j8-wcjf disclosing a maximum-severity (CVSS 10.0, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) unauthenticated SQL injection vulnerability in the Metabase application. The flaw is reachable through the unauthenticated POST /api/session/reset_password endpoint, which the vendor's own attack signature describes as returning an HTTP 400 status code when abused, immediately followed by a successful GET /api/user/current call returning HTTP 200 -- indicating the attacker obtained a valid, authenticated (administrator-capable) session without ever supplying credentials. No CVE identifier has been assigned as of publication; the flaw is tracked solely via the GitHub Security Advisory.
Metabase became aware of the vulnerability not through internal testing but because it was already being exploited against Metabase's own multi-tenant Metabase Cloud SaaS platform, making this a genuine zero-day: real-world attackers found and weaponized the bug before the vendor did. With the session obtained through the injection, an attacker gains full administrator capability inside the Metabase instance: modifying application configuration, reading the credentials Metabase stores for every connected data source (databases, warehouses, and other backends), running arbitrary queries against those connections, and exporting the results. Because Metabase is a BI/analytics layer that sits in front of a customer's actual production and warehouse data, compromising the Metabase layer functions as a trusted-relationship pivot into whatever data those connections expose -- without the attacker ever touching the customer's own infrastructure directly.
The vulnerability affects self-hosted open-source Metabase 0.58.0 through 0.63.3 and the corresponding Enterprise Edition releases 1.58.0 through 1.63.3 (versions 0.57/1.57 and earlier are unaffected); it is fixed in 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5 (and the matching 1.x Enterprise builds). Metabase Cloud instances were patched by the vendor before the public advisory; self-hosted instances required (and in many cases still require) a manual upgrade, and several hosting providers, including Clever Cloud, deployed automatic edge blocking of the reset_password endpoint for at-risk customers as an interim mitigation.
Metabase notified affected Cloud customer Framework (a PC/laptop manufacturer) on 2026-08-06 that its instance had been vulnerable and was accessed by the attacker on 2026-08-03. Framework notified 'all customers' within roughly six hours of learning of the breach; exposed data included customer names, email addresses, login IP addresses, billing/shipping addresses, and phone numbers (and, for Framework for Business accounts, company name, VAT/EIN, and billing email address). Payment and order data were reportedly untouched, and Framework stated it found no evidence of changes to admin access or to systems outside of Metabase. Tally, a form-builder SaaS, separately disclosed that an attacker accessed customer email addresses and one-way password hashes through a compromised Metabase analytics environment (form and submission data were reported unaffected). LexisNexis also disclosed unusual activity affecting third-party-hosted systems including a Metabase API, and disconnected the affected environment pending a forensic investigation; the scope of any data exposure there remains unconfirmed. Metabase has engaged a third-party forensic firm and describes its findings as preliminary. This is not Metabase's first critical pre-authentication flaw: the vendor previously patched CVE-2023-38646 (CVSS 9.8), a pre-auth remote code execution vulnerability, in 2023.
Target sectors: technology, consumer electronics, software-as-a-service, business intelligence and analytics, legal and professional services
Target regions: North America, Global
Timeline
- Attackers exploit the unauthenticated SQL injection zero-day against Metabase Cloud instances belonging to Framework and Tally, obtaining administrator sessions via the reset_password endpoint.
- Metabase identifies the attack activity occurring against its own Metabase Cloud SaaS platform, which is how the previously unknown vulnerability first comes to light.
- Metabase notifies Framework that its instance had been vulnerable to the zero-day and was accessed by the attacker on 2026-08-03.
- Metabase publishes GitHub Security Advisory GHSA-vwf4-m7j8-wcjf describing the unauthenticated SQL injection (CVSS 10.0) and releases patched versions 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5 (plus matching 1.x Enterprise builds).
- Framework notifies 'all customers' of the breach roughly six hours after learning of it, disclosing exposure of names, emails, phone numbers, addresses, and login IPs; states payment data and admin access outside Metabase were unaffected.
- Hosting provider Clever Cloud deploys automatic edge blocking of POST /api/session/reset_password for at-risk Metabase add-on customers still running an affected version.
- Tally discloses that customer email addresses and one-way password hashes were accessed through a compromised Metabase analytics environment; LexisNexis discloses unusual activity affecting third-party-hosted systems including a Metabase API and disconnects the affected environment pending forensic investigation.
- Security Affairs, The Hacker News, and other outlets publish coverage of the active-exploitation zero-day and the Framework/Tally breach disclosures.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 9 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, T1190, T1199, T1098, T1078.004, T1550.004, T1552, T1087, T1213, T1567