Photon Health Data Breach: Zero-Day SQL Injection in Self-Hosted Metabase Exposes Patient Prescriptions
On October 8, 2026, digital healthcare technology company Photon Health published formal breach disclosure notices confirming that an unauthorized third party penetrated its internal infrastructure and accessed sensitive patient medical information. The intrusion was executed via a previously unknown zero-day SQL injection vulnerability in Metabase, an open-source business intelligence platform hosted internally by Photon to analyze prescription routing and pharmacy fulfilment metrics.
Incident Timeline & Technical Root Cause
According to disclosures submitted to state attorneys general and regulatory bodies, the initial intrusion occurred when attackers probed an internet-exposed self-hosted Metabase server. The attackers weaponized a critical unauthenticated SQL injection vulnerability (tied to CVE-2026-72898) located in Metabase's password-reset workflow:
-- Abstraction of vulnerable SQL query in unpatched Metabase password-reset handler
SELECT * FROM core_user
WHERE reset_token = '' OR 1=1 --' AND is_active = TRUE;
Because the query failed to properly parameterize user input before execution against the application database, the attackers extracted the application master password hash and administrative session cookies. Once authenticated as a Metabase administrator, the threat actors leveraged Metabase's native database connector capabilities to query connected internal replica databases holding production prescription transactions.
Compromised Health Information
The forensic investigation concluded on September 4 and confirmed in October that the exfiltrated dataset included:
- Full legal names of patients
- Residential mailing addresses and telephone numbers
- Dates of birth
- Prescription medication details: Drug names, dosages, prescribing physician information, and fill dates.
Photon verified that Social Security numbers and payment card data were not compromised, as the company's data architecture isolates billing systems from clinical routing engines.
The Broader Metabase Exploitation Wave
Photon Health is not an isolated victim. In recent weeks, multiple technology and cloud service providers—including Checkly, Anaconda, and Framework—have reported security compromises linked to unpatched or zero-day vulnerabilities in self-hosted Metabase instances. Business intelligence platforms present an exceptionally high-value target for adversaries: they are frequently configured with read-access credentials across dozens of heterogeneous backend databases, effectively functioning as an unmonitored master key to an organization's most sensitive data repositories.
Defensive Engineering & Architecture Hardening
- Isolate Business Intelligence Tools Behind Zero Trust: Never expose BI tools (Metabase, Superset, Grafana) directly to the public internet. Require access through an identity-aware proxy (IAP) enforcing MFA and device health checks.
- Enforce Least-Privilege Database Roles for BI: Ensure BI database service accounts operate with strictly limited
SELECTprivileges on sanitized views rather than raw production tables. Mask all HIPAA-covered patient identifiers and prescription data at the database layer. - Implement Query Throttling & Export Ceilings: Configure database proxies to alert and sever connections if a single service account attempts to extract more than 1,000 customer records in an automated bulk query.