cybersecurityvulnerabilityzero-daydata-theftmetabase

Metabase SQLi zero-day exploited in customer data-theft attacks

August 7, 2026

Back to all posts

Source: BleepingComputer

A zero-day vulnerability, identified as CVE-2021-35266, has been discovered and is currently being exploited in Metabase, a popular open-source SQL query tool. The flaw, found in the system's XML processing library, allows attackers to execute arbitrary code within affected systems through a specially crafted XML request. This poses a significant risk to Canadian businesses as Metabase is widely used by Small and Medium Businesses (SMBs) for data analysis. With this vulnerability, cybercriminals can potentially steal sensitive data, disrupt operations, or gain unauthorized access to networks. To mitigate this threat, it's crucial for SMB owners and IT managers in Canada to update their Metabase instances immediately to version 0.40.3 or higher.
cybersecurityvulnerabilityzero-daydata-theftmetabase

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment