Available 24/7 · Same-day on-site across Gloucestershire 01452 701355 sales@systemforce.co.uk Remote Help Network Status

Critical Metabase Flaw Under Active Attack: Update Now

Metabase is a popular open-source business analytics tool that lets teams build dashboards and run queries against their databases — no coding required. If your organisation runs a self-hosted Metabase instance, you need to act today.

What has happened?

On 6 August 2026, Metabase disclosed a critical vulnerability tracked as CVE-2026-72898. The flaw sits in the password reset endpoint of the application and allows an attacker to inject malicious SQL commands into the Metabase database without logging in first. By doing so, an attacker can grant themselves full administrator access to your Metabase instance in seconds.

The severity rating is CVSS 10.0 — the maximum possible score. CVSS (Common Vulnerability Scoring System) is the standard way security researchers rate how serious a vulnerability is; a 10.0 means the flaw is remotely exploitable, requires no credentials, and results in complete compromise of the affected system. On 11 August 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-72898 to its Known Exploited Vulnerabilities (KEV) catalogue, confirming that real attackers are actively using this against real organisations right now.

Who is affected?

Any business or organisation running a self-hosted Metabase instance on the following versions is at risk:

  • 0.58.0 to 0.58.23
  • 0.59.0 to 0.59.20
  • 0.60.0 to 0.60.16
  • 0.61.0 to 0.61.10
  • 0.62.0 to 0.62.8
  • 0.63.0 to 0.63.4

Metabase’s own cloud-hosted service was patched automatically before the public disclosure. If you use the cloud version, you are already protected. If you run Metabase on your own server, virtual machine, or container, you are exposed unless you have already applied the patch.

Why does admin access matter so much?

Once an attacker has administrator access to a Metabase instance, they can read all data in every connected database, export records silently, lock out legitimate users by changing credentials, and use Metabase’s database connections as a stepping stone deeper into your network. The data Metabase holds is often highly sensitive precisely because it was set up to answer business questions — customer records, financial reports, operational data. That is exactly what attackers want.

What should you do?

Update immediately. Patched versions are available for every affected major release:

  • 0.58.28
  • 0.59.25
  • 0.60.21
  • 0.61.15
  • 0.62.13
  • 0.63.10

Install the patched version that corresponds to your current major release. Instructions are in the Metabase documentation.

If you cannot update right away, Metabase recommends temporarily blocking access to the /api/session/reset_password endpoint at your firewall or web application firewall (WAF). This removes the attack surface while you arrange the full patch.

After updating, rotate your credentials. Any secret that Metabase holds could have been accessed during the window of exposure: database passwords, LDAP credentials, SMTP credentials, API keys, and cloud warehouse tokens. Even if you have no evidence of a breach, treat these as compromised and change them.

Check your logs. Review your Metabase access logs for unexpected requests to /api/session/reset_password — particularly ones that arrived before you patched. An unusually high volume of requests to that endpoint, or requests from unexpected IP addresses, may indicate an attack attempt.

The wider lesson

Self-hosted business tools — analytics platforms, project management systems, CRM applications — often fall outside the scope of standard patch management. They get deployed, used, and quietly forgotten, with updates applied only when something breaks. CVE-2026-72898 is a reminder that every internet-facing system needs to be included in your patch cycle, however niche it might seem. Our post on network segmentation covers another layer of defence that limits the damage an attacker can cause even if they do get access to one system.

How System Force IT can help

Our managed IT services include proactive patching and vulnerability management across your entire environment — not just the obvious products. We monitor CISA’s Known Exploited Vulnerabilities catalogue and vendor advisories, and we act without waiting to be asked.

If you are concerned about the security of your self-hosted applications, or would like a review of your current patch management arrangements, take a look at our IT security services. Our Cyber Essentials certification support is also a practical starting point for organisations that want to close the most common attack vectors in a structured way.

If you would like help with any of this, get in touch at systemforce.co.uk/contact or call 01452 701355 for a no-obligation chat.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name