Metabase Breach Exposes Downstream Databases

A Metabase compromise can become a database compromise. Once an attacker gets admin in the BI tool, they can reach the credentials it stores for connected systems and pull data from those downstream databases, so patching the app alone does not close the exposure. Metabase says a zero-day SQL injection in versions 1.58 and above was exploited in the wild. The flaw lets an unauthenticated attacker run SQL against the application database, reach admin access, and then steal stored credentials, read data available through those connections, and export it. Cloud instances were already updated; self-hosted deployments have fixed versions in each supported branch. The practical risk is persistence beyond the Metabase patch. If stored database secrets were taken, the attacker may still have access to the connected data sources after Metabase itself is updated.

Part of the PlainSec briefing for 2026-08-08

Editions

Sources