Metabase Patches CVSS 10 Zero-Day Under Active Exploit
Metabase has released a patch for the max-severity unauthenticated SQL injection zero-day confirmed in active exploitation since August 8. Update now. No CVE assigned yet.
Patch is out. If your Metabase instance is reachable from untrusted networks and you haven’t updated, that window needs to close today.
Metabase has released a fix for the unauthenticated SQL injection zero-day that entered active exploitation on August 8. Vendor-stated CVSS: 10.0. No CVE identifier assigned as of this writing.
Timeline
- August 8 — Active exploitation confirmed. An unauthenticated remote attacker can inject arbitrary SQL through Metabase’s application layer and escalate to full admin access. No patch. No CVE. Affected version ranges not disclosed. Metabase issued a warning; no standalone security advisory URL published.
- August 10 — Patch released. SecurityWeek confirmed the fix. Consult Metabase’s official release announcement for the specific patched version number.
What the Flaw Does (Confirmed)
Unauthenticated SQL injection through the Metabase application layer. Successful exploitation yields full administrative access. Every data source the instance is configured to reach — production databases, warehouses, analytics backends — is in scope once admin access is established.
Vendor characterization: CVSS 10.0. That figure is vendor-acknowledged, not independently verified against an NVD record, because no NVD record exists yet.
What to Do
- Update immediately. Check Metabase’s release page for the specific patched version and apply it.
- Review logs from August 8 onward. Look for unauthorized session creation, unexpected admin logins, unusual data source queries, or privilege escalation events.
- Audit connected data sources. Everything Metabase can reach was in scope during the exposure window. Know what that is.
- Confirm Metabase Cloud status. If you’re on the managed SaaS tier, contact Metabase support to confirm your instance is protected.
Status (as of 2026-08-10T13:00Z)
- Patch: confirmed released — SecurityWeek
- CVE: not yet assigned
- CISA KEV: not listed (exploitation profile fits KEV criteria — watch for addition)
- Attacker identity: unknown
- Victim count: unknown
Exploitation was active for at least two days before a fix was available. The full scope of compromise is unconfirmed.
Track current KEV additions at our KEV tracker.
Found this useful? Share it.


