Dataminr INTEL BRIEF

Unauthenticated SQL Injection in Metabase (CVE-2026-72898) Exposes Thousands of Self-Hosted Instances; ShinyHunters Leak-Site Listing Unconfirmed

Unauthenticated SQL injection in Metabase (CVE-2026-72898) lets attackers gain admin database access without credentials. Dataminr's scan found thousands of self-hosted instances still unpatched.

Unauthenticated SQL Injection in Metabase (CVE-2026-72898) Exposes Thousands of Self-Hosted Instances; ShinyHunters Leak-Site Listing Unconfirmed
DATE August 12, 2026
AUTHOR Jeanette Miller-Osborn, Field Cyber Intelligence Officer
SHARE
  • Subscribe via RSS
CYBER DEFENSE

Key Takeaways

  • Critical, actively exploited flaw: An unauthenticated SQL injection in Metabase (version 0.58+), reachable via the /api/session/reset_password endpoint, grants administrator access to the application database, including connected-database credentials. Exploitation predates public disclosure and CVE assignment.
  • Confirmed victims have already surfaced: Framework, Anaconda and n8n, which are all Metabase Cloud tenants, have disclosed unauthorized customer-data access from the pre-patch window. n8n tied it to CVE-2026-72898.
  • Massive unpatched exposure: Of ~11,000 probable self-hosted Metabase instances found via internet-wide scanning, 4,309 were potentially vulnerable, and over 97% of fingerprinted hosts on affected branches appeared unpatched.
  • High-value sectors implicated, ownership attribution incomplete: Likely-vulnerable instances span government, healthcare, energy, finance, telecom, aviation, and large public organizations. Shared cloud IP space obscures true ownership, so real exposure among major organizations is almost certainly undercounted.
  • Possible ShinyHunters attribution: A “Metabase” listing has appeared on the ShinyHunters-branded extortion blog. However, the entry is a placeholder with no scope named and only 7 GB of related data published, in contrast to the other listings on the site.
  • Additional Metabase advisory August 11: Metabase released a second advisory, GHSA-r495-55cx-fjh7, addressing multiple additional vulnerabilities, with corresponding CVEs not immediately disclosed.

Incident Overview

On August 6, 2026, Metabase disclosed a critical unauthenticated SQL injection affecting self-hosted deployments on version 0.58 and above, exploitable via the /api/session/reset_password endpoint. The flaw grants administrator access to the application database, including credentials for any connected databases. Metabase Cloud was also affected but patched before disclosure. The CVE, 2026-72898, was assigned August 10 and exploitation in the wild predates both the patch and the disclosure.

A “Metabase” listing has appeared on ShinyHunters-branded extortion blog, where various other extortion campaigns have been listed in 2026. Three Metabase Cloud tenants have disclosed incidents so far with one attributing it to CVE 2026-72898.

The Dataminr Threat Research and Cyber Engineering team (TRACE) conducted a broad exposure assessment on August 8, with approximately 11,000 hosts observed as probable self-hosted Metabase deployments. Of those, 4,309 were likely running vulnerable versions. Many exposed hosts span critical infrastructure sectors including government, healthcare, energy, finance, telecom, aviation, and large public organizations. Over 97% of fingerprinted hosts on an affected branch appeared unpatched.

Note: Ahead of publishing this brief, Dataminr reached out to organizations identified in this assessment as likely running an exposed self-hosted instance, so they could confirm and act on their exposure directly. TRACE’s assessment covers self-hosted Metabase deployments only, including those hosted on cloud infrastructure such as AWS, and does not extend to Metabase Cloud tenants, which TRACE has no visibility into. This outreach is unlikely to represent the full scope of exposure given the attribution limitations noted in the brief. If your organization uses a self-hosted instance and you are unsure whether you’ve been contacted or whether you’re affected, please reach out to Dataminr.

Technical Details

The vulnerability is an unauthenticated SQL injection exploitable via /api/session/reset_password, granting administrator access to the Metabase application database and any connected data sources, a path to lateral compromise beyond Metabase itself. Affected branches run x.58 through x.63. Per Metabase’s initial GitHub Security Advisory (GHSA-vwf4-m7j8-wcjf), fixed releases are 0.58.28, 0.59.25, 0.60.21. 0.61.15, 0.62.13, and 0.63.10, with corresponding Enterprise builds; confirm the exact target version against the current advisory. Metabase Cloud was patched by disclosure; self-hosted deployments remain exposed until upgraded.

On the CVE itself: Metabase initially disclosed the vulnerability on August 6 without a CVE identifier, tracking it only via its GitHub Security Advisory (GHSA-vwf4-m7j8-wcjf, CVSS 10.0). CVE-2026-72898 was assigned four days later, on August 10. 

Passive scan data can’t confirm whether the endpoint was actually reachable at scan time, and some vulnerable-version environments may already have compensating WAF or network controls, so vulnerable doesn’t mean confirmed-exploitable. Raising urgency, a researcher published an analysis and a PoC lab on August 8, lowering the bar for further weaponization. 

Immediate Actions and Recommendations

Patch by upgrading all self-hosted Metabase deployments to the patched release for their branch (0.58.28, 0.59.25, 0.60.21. 0.61.15, 0.62.13, and 0.63.10; Enterprise equivalents apply), confirming the exact version against the current advisory before deploying. 

Confirm mitigation status rather than relying on scan data: check whether /api/session/reset_password is genuinely reachable from untrusted networks, and validate any existing WAF or network controls gating it.

Block or restrict external access to that endpoint at the network or WAF layer within the hour where immediate patching isn’t feasible. This is Metabase’s own published workaround. 

Revoke all active sessions immediately after patching by deleting all rows in the core_session table, per vendor guidance, invalidating anything established via the pre-patch exploit. Within 24 hours, rotate credentials for any database connected to Metabase, given the vulnerability’s direct path to credential exposure.

Threat hunt regardless of patch timing over the first 24 to 48 hours. Review Metabase activity and query history, plus connected-database access logs, for anomalous admin actions, password-reset activity, or unexpected queries predating the patch, since exploitation is confirmed to predate disclosure.

Resources

2026 Mid-Year Threat Landscape Report

The first half of 2026 was defined by a widening gap between attack speed and defense speed — and AI is accelerating both sides. Dataminr’s 2026 Cyber Threat Landscape Mid-Year Report pulls from 4,500 threat actors tracked, 73,000 vulnerabilities detected, and over 2 million alerts processed per month to surface what actually mattered in H1 and what teams need to prepare for in H2.

Download Report

Aug 12, 2026

SHARE
  • Cyber Defense
  • Cyber Risk
  • Intel Brief