HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Unauthenticated SQL Injection in Metabase (v1.58+) Enables Data Theft from SaaS and Self‑Hosted Instances

Metabase disclosed a zero‑day, unauthenticated SQL injection (CVSS 10.0) affecting versions 1.58 through 0.63 that has been used to steal customer data. The incident underscores the need for SOC 2‑aligned patch‑management and continuous evidence collection.

LiveThreat™ Intelligence · 📅 August 08, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Critical Unauthenticated SQL Injection in Metabase (v1.58+) Enables Data Theft from SaaS and Self‑Hosted Instances

What Happened — A zero‑day, unauthenticated SQL injection flaw in Metabase versions 1.58 through 0.63 allows an attacker to execute arbitrary SQL, gain administrator rights, and exfiltrate data from both Metabase Cloud and self‑hosted deployments. The vulnerability (rated CVSS 10.0) has been actively exploited against customers such as Framework and Tally, resulting in confirmed data‑theft incidents. Metabase has issued a fix and recommends immediate remediation.

Why It Matters for Compliance & Audit Readiness

  • The scenario maps directly to SOC 2 CC6.1 (change management) and CC7.1 (risk mitigation) – controls that require documented patch‑management processes and evidence of timely remediation.
  • Continuous‑compliance programs must capture patch‑deployment evidence and validate that vulnerable endpoints are blocked, providing a defensible audit trail.
  • Demonstrating real‑time monitoring of critical application vulnerabilities aligns with the Control Mapping capability, turning a technical fix into verifiable compliance evidence.

Who Is Affected — SaaS analytics providers, self‑hosted business‑intelligence platforms, and any organization that integrates Metabase for data visualization (primarily TECH_SAAS and other data‑driven enterprises).

Recommended Actions

  • Upgrade all Metabase instances to the minimum safe releases (≥ 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, 0.63.5).
  • Temporarily block the /api/session/reset_password endpoint until patches are applied.
  • Revoke all active user sessions, rotate database credentials, and audit API keys and admin accounts for unauthorized changes.
  • Review logs for the POST /api/session/reset_password → 400 followed by a successful GET /api/user/current pattern.
  • Document remediation steps in your change‑management system to satisfy SOC 2 evidence requirements.

Technical Notes — The flaw is an unauthenticated SQL injection (SQLi) that grants admin access, enabling credential theft and arbitrary data export. No CVE ID has been assigned; Metabase’s advisory rates it Critical with CVSS 10.0. Affected versions: 1.58 and above (branches 0.58‑0.63).

Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →