Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Deadly Zero-Day Exploit in Metabase: Exposing Admin Access and Sensitive Data




A deadly zero-day exploit in Metabase exposed admin access and sensitive data of its customers, revealing a grim reminder of the importance of patching vulnerabilities promptly and regularly updating software. According to Metabase, an unauthenticated attacker was able to inject arbitrary SQL into the platform's application database, granting access to administrator rights over the entire instance.

The vulnerability affected versions 1.58 to 63, with a specific patched point release for each. This exploit highlights the urgency of addressing zero-day vulnerabilities and emphasizes the need for prompt patching and regular software updates.



  • Metabase suffered a zero-day exploit exposing admin access and customer sensitive data.
  • The vulnerability had a CVSS score of 10 and was found in versions 1.58 to 63.
  • An unauthenticated attacker could inject arbitrary SQL, gaining administrator rights.
  • Patched point releases were available for each affected version (0.58.24-0.63.5).
  • A specific attack signature has been published to help detect and prevent exploitation.
  • Customers on older point releases need to update immediately, as those on version 57 or earlier are in the clear.
  • Metabase is recommending customers take additional steps for cleanup, including wiping active sessions and rotating credentials.



  • Metabase, an open-source business intelligence (BI) and data analytics platform, recently suffered a devastating zero-day exploit that exposed admin access and sensitive data of its customers. The vulnerability, identified by the company as a CVSS 10 score, was found in versions 1.58 to 63, with a specific patched point release for each.

    The exploit allowed an unauthenticated attacker to inject arbitrary SQL into the Metabase application database, granting access to administrator rights over the entire instance. This opened up a wide range of possibilities for attackers, including changing application configuration, stealing stored credentials for connected databases, reading accessible data, and exporting it all out.

    According to the advisory published by Metabase, the vulnerability was exploited as a genuine zero-day, meaning that real attackers found it before the company did, and Metabase only learned about it because it was already being used against Metabase Cloud itself. This timeline highlights the urgency of patching the vulnerability, especially for customers running self-hosted instances.

    The affected range spans versions 58 through 63, with a specific patched point release for each: 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5. Customers running version 57 or earlier are in the clear, but those on older point releases need to update immediately.

    Metabase has taken steps to address the issue by blocking the /api/session/reset_password endpoint at the network level until the patch lands. Additionally, the company published a specific attack signature worth checking logs against right now, which is indicated by a call to POST /api/session/reset_password with a 400 status code followed by a call to GET /api/user/current with a 200 status code.

    The cleanup list for customers who have had their reset-password endpoint publicly reachable is longer than a simple patch. Metabase recommends wiping every active session, auditing API keys for anything unrecognized, checking administrator accounts for unexpected changes, rotating credentials on every connected database, and combing through both data warehouse logs and Metabase's own query history for signs someone poked around where they shouldn’t have.

    At least one real-world casualty has already surfaced. PC maker Framework confirmed that it was hit through this flaw, notifying customers that names, login IPs, addresses, phone numbers, and email addresses were accessed during the breach, though the company said no order or payment information was touched.

    In conclusion, the Metabase zero-day exploit serves as a stark reminder of the importance of patching vulnerabilities promptly and regularly updating software to prevent such breaches. With this incident, Metabase has once again demonstrated its commitment to the security and integrity of its customers' data.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Deadly-Zero-Day-Exploit-in-Metabase-Exposing-Admin-Access-and-Sensitive-Data-ehn.shtml

  • https://securityaffairs.com/196874/hacking/metabase-zero-day-exploited-in-the-wild-exposing-admin-access-and-sensitive-data.html


  • Published: Sat Aug 8 07:42:25 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us