- Sources: primary, advisory, discussion
- Summary: Checkly states an attacker exploited a zero-day in Metabase Cloud on 2026-08-03 and read its analytics warehouse for about 26 minutes. Checkly states Metabase discovered the intrusion the same day, blocked the endpoints used, patched the vulnerability, and published a security update, that customers, law enforcement, and a third-party forensics firm were notified on 2026-08-06, and that Checkly closed its investigation on 2026-08-10. The post names the data at risk and lists what customers should rotate. Metabase published advisory GHSA-r495-55cx-fjh7 on 2026-08-11 at Critical severity with no CVE assigned, patched in x.58.28, x.59.25, x.60.21, x.61.15, x.62.13, and x.63.10, and it lists OSS and EE jar and docker artifacts for each, so self-hosted installations are in scope and have a named upgrade target. That advisory describes hardening the project identified proactively across query validation, permission checks on nested references, rate limiting, sandboxing and impersonation, and network exposure, and it attributes no item to the Checkly intrusion, so the link between the advisory and the exploited zero-day is not established here.
- Why it matters: Self-hosted operators now have a Critical advisory with a fixed version for every supported major line, and Checkly customers who placed authorization headers, cookies, or query string parameters directly in a check configuration, or who use OTEL API keys, have a named rotation list and the 2026-08-03 window to search their logs against.
- Follow-up: Whether Metabase states which issue was the one exploited against Metabase Cloud.
send feedback on this story