{"id":893,"date":"2026-08-10T11:30:01","date_gmt":"2026-08-10T06:00:01","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=893"},"modified":"2026-08-19T11:30:17","modified_gmt":"2026-08-19T06:00:17","slug":"metabase-sql-injection-zero-day-patch-now-rotate-credentials","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/","title":{"rendered":"Metabase SQL Injection Zero-Day: Patch Now, Rotate Credentials"},"content":{"rendered":"<p>Metabase disclosed on August 6 that attackers had exploited an unauthenticated SQL injection zero-day against its Cloud platform. Metabase CEO Sameer Al-Sakran said in a company blog post that the flaw affects versions 1.58 and above, using Metabase&#8217;s Enterprise Edition numbering. The Open Source Edition uses a separate 0.x scheme for the same fix. Self-hosted deployments are included.<\/p>\n<p>Two Metabase customers have already confirmed the fallout. Framework, the modular laptop maker, disclosed that attackers accessed its customer data through a compromised Metabase environment. Tally, the online form builder, made a similar disclosure. The details of what each company lost differ, but both point to the same root cause.<\/p>\n<p>For self-hosted administrators, attackers are actively exploiting this vulnerability, and it has already caused confirmed <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-data-theft\/\">data-theft<\/a> incidents. The response must extend beyond patching alone.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How an unauthenticated endpoint became an admin takeover<\/h2>\n<p>A single unauthenticated endpoint is behind the entire incident. Here&#8217;s how a password-reset request turned into administrator access and stolen data.<\/p>\n<ul>\n<li>Metabase published security advisory GHSA-vwf4-m7j8-wcjf on GitHub on August 6, covering an unauthenticated SQL injection <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-vulnerability-in-cybersecurity\/\">vulnerability<\/a> affecting the Metabase application database.<\/li>\n<li>The flaw sits in the public POST <code>\/api\/session\/reset_password<\/code> endpoint. No login is required to reach it.<\/li>\n<li><a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-attack-chain\/\">Attack chain<\/a>: SQL injection leads to administrator access, then to configuration changes, stolen database credentials, and exported data.<\/li>\n<li>CVSS 10.0 comes from <code>AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H<\/code>. The Scope Changed (S:C) component is the differentiator. Without it, the same profile would cap at 9.8.<\/li>\n<li>Security reporting flags a possible compromise pattern: a POST to<code> \/api\/session\/reset_password<\/code> returning HTTP 400, followed by a successful GET to<code> \/api\/user\/current<\/code>. Treat this as an investigation lead, not confirmed proof of compromise.<\/li>\n<\/ul>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/threat-analysis-.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What is Threat Analysis?<\/h4><p>Beginner's guide to threat analysis process, types, and XDR support.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-is-threat-analysis\/\" aria-label=\"What is Threat Analysis?\"><\/a><\/div><\/div><\/div>\n<h2>Framework and tally: What attackers actually reached<\/h2>\n<p>Framework and Tally have each confirmed they were victims of the Metabase SQL injection zero-day. Their disclosures show what administrator access exposed, on each side.<\/p>\n<p>Framework:<\/p>\n<p>Metabase notified the company on August 6 that an attacker had accessed its instance on August 3. Framework rotated its credentials and found no evidence of access to systems outside Metabase. Framework confirmed the exposure covered customer names, email addresses, physical addresses, phone numbers, and login IP addresses. Payment and order data were not affected.<\/p>\n<p>Tally:<\/p>\n<p>Attackers compromised its Metabase analytics environment on the same date, August 3. The breach exposed user email addresses and passwords stored as a cryptographic hash. Tally stores form submissions and their answers separately, and said they were not exposed. Initially, Tally had not confirmed which hashing algorithm it uses or whether it salted the exposed hashes.<\/p>\n<h3>Attack path at a glance<\/h3>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 21.0359%; text-align: left;\">Attack Stage<\/th>\n<th style=\"width: 38.2664%; text-align: left;\">What Happened<\/th>\n<th style=\"width: 39.6406%; text-align: left;\">Operational Risk<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 21.0359%;\">Initial access<\/td>\n<td style=\"width: 38.2664%;\">Unauthenticated attacker reaches <code>\/api\/session\/reset_password<\/code> with no credentials<\/td>\n<td style=\"width: 39.6406%;\">Affected, unpatched instances with the vulnerable <code>\/api\/session\/reset_password<\/code> endpoint publicly accessible are exposed to unauthenticated remote compromise<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 21.0359%;\">SQL injection<\/td>\n<td style=\"width: 38.2664%;\">Attacker injects arbitrary SQL into Metabase&#8217;s application database<\/td>\n<td style=\"width: 39.6406%;\">Attacker can manipulate application data and potentially change Metabase configuration<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 21.0359%;\">Privilege escalation<\/td>\n<td style=\"width: 38.2664%;\">Injected SQL can give the attacker administrator access to the Metabase instance<\/td>\n<td style=\"width: 39.6406%;\">Attacker can alter configuration, accounts, and API keys<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 21.0359%;\">Credential exposure<\/td>\n<td style=\"width: 38.2664%;\">Admin access exposes stored credentials for connected databases<\/td>\n<td style=\"width: 39.6406%;\">Stolen database credentials can enable further access to connected data sources, depending on their network accessibility and authorization controls<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 21.0359%;\">Data theft<\/td>\n<td style=\"width: 38.2664%;\">Attacker reads and exports data available through those connections<\/td>\n<td style=\"width: 39.6406%;\">Confirmed at Framework and Tally, both exposing customer records<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Self-hosted response checklist<\/h2>\n<p>Metabase&#8217;s advisory lays out a specific sequence for any self-hosted instance that had the affected endpoint publicly reachable:<\/p>\n<ul>\n<li>Upgrade to the fixed release for your branch: 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5 (Open Source Edition). Enterprise Edition customers should move to the matching 1.x build, for example 1.63.5.<\/li>\n<li>If an immediate upgrade is not possible, block the \/api\/session\/reset_password endpoint as a temporary measure.<\/li>\n<li>Revoke every active session by clearing the application&#8217;s session table.<\/li>\n<li>Review <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-api-key\/\">API keys<\/a> and delete anything unrecognized.<\/li>\n<li>Check administrator accounts for unexpected changes.<\/li>\n<li>Rotate credentials for every database connected to Metabase.<\/li>\n<li>Review data warehouse and Metabase query-history logs for signs of <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-unauthorized-access\/\">unauthorized access<\/a>.<\/li>\n<\/ul>\n<p>Patching the Metabase application does not rotate credentials for the databases it connects to. Those are separate systems, and they need separate attention.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity framework\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity framework\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Building a cybersecurity framework for your enterprise\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Breaks down key cybersecurity framework types and explains how UEM helps strengthen enterprise security posture.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/building-a-cybersecurity-framework-for-your-enterprise\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Where Hexnode helps here<\/h2>\n<p>Hexnode has a role here, but a narrow one. Here&#8217;s what UEM and XDR can each do for this incident, and where the line sits.<\/p>\n<h3>Hexnode UEM<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can support patch and configuration compliance for the servers and admin workstations that host a self-hosted Metabase deployment, across Windows and macOS devices.<\/li>\n<li>It can support patch and configuration compliance for the host server OS and admin endpoints that run a self-hosted Metabase deployment, across Windows, macOS, and Linux. It secures the underlying host, not the Metabase web application itself.<\/li>\n<\/ul>\n<h3>Hexnode XDR<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a>\u00a0 can detect host-level process anomalies on managed endpoints, primarily Windows, that may surface after exploitation. It does not parse or inspect web-layer SQL traffic.<\/li>\n<li>It can detect host-level process anomalies on managed endpoints, primarily Windows, that may surface after exploitation. Identifying vulnerabilities in Metabase and reviewing its application logs or query history remain separate administrative tasks.<\/li>\n<\/ul>\n<p>Reviewing Metabase&#8217;s own activity logs and applying the vendor&#8217;s patch remain the administrator&#8217;s responsibility, with Metabase support where applicable.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Has Metabase assigned a CVE for this vulnerability?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. The advisory (GHSA-vwf4-m7j8-wcjf) has no assigned CVE yet. The flaw still carries a Critical rating and a CVSS score of 10.0.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Are Metabase Cloud customers still at risk?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Metabase has upgraded all Cloud instances, and they are no longer vulnerable to this flaw. If an attacker accessed a customer&#8217;s instance before the fix, that customer may still need to investigate. They may also need to address any resulting exposure.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does installing the patch alone resolve exposure if an instance was already compromised?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Patching closes the entry point but doesn&#8217;t undo access or credentials already stolen. Instances with the endpoint publicly reachable should be treated as compromised, requiring the full response checklist, including session revocation and credential rotation.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The version number tells administrators almost nothing about whether the Metabase SQL injection flaw actually touched an instance. Self-hosted administrators should treat the version upgrade as the starting point of their response, not the end of it.<\/p>\n<p>Organizations that ran an affected version with the vulnerable reset-password endpoint publicly accessible should complete Metabase&#8217;s post-upgrade response steps and review logs for the documented attack pattern; credential rotation mitigates exposure but does not determine whether compromise occurred. A clean version number does not, by itself, confirm a clean instance.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Analytics Platforms Are Now Attack Surface <\/h5><p>Hexnode helps enforce patch compliance and monitor endpoint access anomalies. <\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Metabase disclosed on August 6 that attackers had exploited an unauthenticated SQL injection zero-day against&#8230;<\/p>\n","protected":false},"author":5,"featured_media":894,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12,13],"class_list":["post-893","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zero-day","category-identity-abuse","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Metabase SQL Injection Zero-Day: What to Patch Now<\/title>\n<meta name=\"description\" content=\"A critical Metabase SQL injection zero-day let attackers steal customer data. Self-hosted admins must patch now.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Metabase SQL Injection Zero-Day: What to Patch Now\" \/>\n<meta property=\"og:description\" content=\"A critical Metabase SQL injection zero-day let attackers steal customer data. Self-hosted admins must patch now.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-10T06:00:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T06:00:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/metabase-sql-injection.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Metabase SQL Injection Zero-Day: Patch Now, Rotate Credentials\",\"datePublished\":\"2026-08-10T06:00:01+00:00\",\"dateModified\":\"2026-08-19T06:00:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/\"},\"wordCount\":1144,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/metabase-sql-injection.jpeg?format=webp\",\"articleSection\":[\"Zero-Day\",\"Identity Abuse\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/\",\"name\":\"Metabase SQL Injection Zero-Day: What to Patch Now\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/metabase-sql-injection.jpeg?format=webp\",\"datePublished\":\"2026-08-10T06:00:01+00:00\",\"dateModified\":\"2026-08-19T06:00:17+00:00\",\"description\":\"A critical Metabase SQL injection zero-day let attackers steal customer data. Self-hosted admins must patch now.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/metabase-sql-injection.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/metabase-sql-injection.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"metabase sql injection\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Metabase SQL Injection Zero-Day: Patch Now, Rotate Credentials\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Metabase SQL Injection Zero-Day: What to Patch Now","description":"A critical Metabase SQL injection zero-day let attackers steal customer data. Self-hosted admins must patch now.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/","og_locale":"en_US","og_type":"article","og_title":"Metabase SQL Injection Zero-Day: What to Patch Now","og_description":"A critical Metabase SQL injection zero-day let attackers steal customer data. Self-hosted admins must patch now.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-10T06:00:01+00:00","article_modified_time":"2026-08-19T06:00:17+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/metabase-sql-injection.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Metabase SQL Injection Zero-Day: Patch Now, Rotate Credentials","datePublished":"2026-08-10T06:00:01+00:00","dateModified":"2026-08-19T06:00:17+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/"},"wordCount":1144,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/metabase-sql-injection.jpeg?format=webp","articleSection":["Zero-Day","Identity Abuse"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/","url":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/","name":"Metabase SQL Injection Zero-Day: What to Patch Now","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/metabase-sql-injection.jpeg?format=webp","datePublished":"2026-08-10T06:00:01+00:00","dateModified":"2026-08-19T06:00:17+00:00","description":"A critical Metabase SQL injection zero-day let attackers steal customer data. Self-hosted admins must patch now.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/metabase-sql-injection.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/metabase-sql-injection.jpeg?format=webp","width":1340,"height":700,"caption":"metabase sql injection"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/metabase-sql-injection-zero-day-patch-now-rotate-credentials\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Metabase SQL Injection Zero-Day: Patch Now, Rotate Credentials"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/893","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=893"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/893\/revisions"}],"predecessor-version":[{"id":896,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/893\/revisions\/896"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/894"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}