# Metabase zero-day SQL injection exploitation

> Live situation record from CLSTR: https://clstr.news/situations/metabase-zero-day-sql-injection-exploitation
> Updated: 2026-08-09T23:23:50.000Z. Sources: 9. Developments: 2.

A critical zero-day SQL injection vulnerability in Metabase software was identified as having been actively exploited since August 3, 2026. The flaw, which carries a maximum CVSS score of 10.0, allows unauthenticated attackers to execute arbitrary database queries, potentially gaining administrative access to both self-hosted installations and Metabase Cloud services.

The breach resulted in the theft of sensitive customer data, including names, contact information, and billing details. Several organizations, including Framework, Tally, and the Italian defense supplier Marconi Industrial Services, have been identified as victims. Reports indicate that ransomware groups, such as the group known as Play, have leveraged the vulnerability to steal data and encrypt systems for extortion purposes.

Metabase has released patches for the vulnerability and advised users to update immediately, rotate credentials, and conduct forensic investigations to check for unauthorized access.

## Timeline

### 2026-08-09: Metabase software faces critical CVSS 10.0 zero-day exploitation

A critical CVSS 10.0 zero-day vulnerability in Metabase is being actively exploited by ransomware groups to steal and encrypt data, affecting various organizations including defense suppliers.

2 sources. https://clstr.news/cluster/metabase-software-faces-critical-cvss-100-zero-day-exploitation

### 2026-08-07: Metabase patches critical zero‑day SQL injection after data breach

Metabase fixed a critical zero‑day SQL injection used to steal customer data from its SaaS and self‑hosted products, affecting clients like Framework and Tally; users urged to update and rotate credentials.

7 sources. https://clstr.news/cluster/metabase-patches-critical-zeroday-sql-injection-after-data-breach

---
Cite as: Metabase zero-day SQL injection exploitation. CLSTR, https://clstr.news/situations/metabase-zero-day-sql-injection-exploitation
