Metabase announces security update for 0-day vulnerability
Attackers exploited an unknown vulnerability in versions 1.58 and above; self-hosted instances should upgrade immediately and revoke active sessions.
See the latest news and media coverage for Metabase. We track all announcements, press releases, and industry mentions in real time, all in one place.
Open-source business intelligence and embedded analytics platform
metabase.comLast updated
In short: Metabase patched a critical zero-day SQL injection vulnerability after it was exploited to breach customer data at several organizations.
Attackers exploited an unknown vulnerability in versions 1.58 and above; self-hosted instances should upgrade immediately and revoke active sessions.
It adds treemap charts, two-factor authentication, PDF subscriptions, and support for more LLM providers for Metabot.
It also released MCP server, Metabot in Slack, Data Studio, and more, calling it an interim report.
The update includes MCP server charts, CLI for terminal management, an interactive Schema Viewer, and library organization.
Attackers exploited a critical Metabase vulnerability to breach Mathspace after the company failed to patch its self-hosted ...
CVE-2026-72898 is a critical unauthenticated SQL injection in Metabase's password-reset functionality. Learn more about it.
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
Metabase CEO Sameer Al-Sakran wrote in a company blog post that the flaw was an unauthenticated SQL injection vulnerability that could ultimately give a remote...
Track Metabase and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to Metabase and other trending companies.