Metabase zero‑day attack: protect your business data now

Why you should read this now
If your business relies on Metabase for dashboards, sales reports or any other analytics, a brand‑new vulnerability is being exploited in the wild. An attacker can walk straight into the admin console without a password, read every connected database and even export data. In plain terms: your customer list, sales figures and any other sensitive information could be exposed right now unless you act immediately.
What the vulnerability does
Metabase announced a critical zero‑day SQL injection (CVSS 10.0) that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database. SQL injection is a way of tricking a database into running your own commands, like a hacker slipping a malicious note into a form that the system then executes. The injected code gives the attacker administrator privileges inside the Metabase instance. With admin rights they can:
- Change Metabase configuration
- Steal stored credentials for every database that Metabase connects to
- Read and export any data those databases contain
- Create or delete user sessions, effectively locking out legitimate users
The flaw affects all self‑hosted Metabase versions from 1.58.0 up to but not including 1.58.23, 1.59.0‑1.59.20, 1.60.0‑1.60.15, 1.61.0‑1.61.9, 1.62.0‑1.62.7, and 1.63.0‑1.63.2. Metabase Cloud customers have already received the fix, but anyone running Metabase on their own servers must patch right away.
Immediate actions & a temporary workaround
1. Patch or isolate right now
- If you can update – download the latest Metabase release (≥ 1.58.24, 1.59.21, 1.60.17, 1.61.11, 1.62.9, 1.63.5) from the official Metabase website and apply it to your server. This removes the vulnerability completely.
- If you cannot patch immediately – isolate the Metabase service from the internet. Block external access to the Metabase URL and only allow trusted internal IPs. This buys you time while you arrange the update.
Quick temporary workaround while you arrange a patch
Until the patch is applied, block the /api/session/reset_password endpoint at your firewall or reverse‑proxy level. This endpoint is the first step attackers use to gain a foothold. Blocking it stops the most common exploit chain, though it does not replace a proper patch.
Why rapid action matters for small businesses
For a bakery juggling three booking systems, a dental clinic storing patient records, or a local retailer with an online shop, a breach can mean hefty GDPR fines, loss of customer trust, and costly downtime. Even a few hours of inaccessible dashboards can halt sales reporting, delay inventory orders, and damage your reputation. Acting within hours dramatically reduces the chance of data loss and keeps your business running smoothly.
Post‑patch checklist – what to do after you’ve updated
-
Revoke all active sessions
Connect to the Metabase application database and delete every row in thecore_sessiontable. This forces every user to log in again, kicking out any hidden attacker sessions. -
Review and clean admin accounts and API keys – delete any you don’t recognise and generate new keys for needed integrations.
-
Audit administrator accounts
Check the list of admin users for unexpected accounts or changes to existing ones. Remove any that you did not create. -
Rotate credentials for every connected database
Change usernames and passwords for all databases that Metabase queries (MySQL, PostgreSQL, Snowflake, etc.). Update the connection details in Metabase afterwards. -
Inspect logs for suspicious activity
- Look for a pattern of
POST /api/session/reset_passwordreturning a 400 status followed byGET /api/user/currentreturning 200. - Review database query logs for unexpected large data exports.
- Check your data‑warehouse audit logs for unknown IP addresses or times.
- Look for a pattern of
-
Back‑up your Metabase configuration
After the patch, export the Metabase settings and store them securely. This makes future restores faster and reduces downtime.
Taking these steps within hours, not days, dramatically reduces the chance that an attacker can steal or corrupt your data.
FAQ – Metabase zero‑day questions small business owners ask
Q: I use Metabase Cloud – do I need to do anything?
A: Metabase Cloud instances have already been updated to the safe version. Still, it’s good practice to review your API keys and rotate database credentials, because the breach could have affected any self‑hosted components you integrate with.
Q: My Metabase server is behind a corporate firewall. Is the risk lower?
A: The vulnerability works over the internet, but also over any network the attacker can reach. If the server is only accessible from your internal network, the risk is reduced, yet an insider or compromised internal device could still exploit it. Patch as soon as possible.
Q: Can I use a third‑party patching tool?
A: We recommend using the official Metabase release package. Third‑party tools may not apply the exact fix and could introduce new issues.
Keep your analytics safe with IT Move NL
A security incident like this can happen to any small business that runs analytics on its own servers. The fastest way to stay protected is to combine rapid patch management with ongoing vulnerability monitoring and credential rotation.
If you’d rather have an expert handle the patch and keep an eye on future threats, we’re here to help. Learn how our rapid patch management protects small businesses from zero‑day attacks.
Sources:

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent
Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.
STAY IN THE LOOP
// Cloud, AI & DevOps insights — straight to your inbox.
No spam. Unsubscribe anytime.
Need help with your cloud infrastructure?
Our team of experts is ready to help you navigate the complexities of modern cloud architecture.
Get in Touch