Ethical Hacking News
Metabase Zero-Day Exploited in Wild: A Critical Security Flaw Exposed, allowing unauthenticated remote attackers to inject arbitrary SQL into the Metabase application database, granting them administrator access to the instance. Update your systems now.
Metabase's popular business intelligence and data visualization software package has been compromised due to a critical zero-day vulnerability (CVSS score: 10.0) allowing unauthenticated remote attackers to inject arbitrary SQL into the Metabase application database. The attack primarily targets versions 1.58 and above of Metabase Cloud, as well as self-hosted instances running versions x.58.0 through x.63.3, with all affected users being advised to apply security patches immediately. The vulnerability allows attackers to access sensitive data, manipulate application configurations, steal stored credentials, read accessible data, and export data. Customers of self-hosted instances have already received updated patches, while users of Metabase Cloud can rest assured that their instance has been updated to the latest version. The attack is attributed to at least one company, Framework, which suffered a breach resulting in customer names and login IPs being accessed without access to order or payment information. The incident highlights the importance of keeping systems up-to-date with the latest security patches and emphasizes the need for robust cybersecurity measures and proactive security strategies to prevent zero-day attacks.
The cybersecurity landscape has been dealt a significant blow with the recent exploitation of a critical zero-day vulnerability in Metabase, a popular business intelligence and data visualization software package. The vulnerability, which carries an extremely high CVSS score of 10.0, allows unauthenticated remote attackers to inject arbitrary SQL into the Metabase application database, granting them administrator access to the instance.
The attack, which was first identified by security researchers, targets versions 1.58 and above of Metabase Cloud, as well as self-hosted instances running versions x.58.0 through x.63.3. According to Metabase, these versions have already been updated to the latest patch, but users are advised to apply security patches released by the company with immediate effect.
The vulnerability in question allows an attacker to inject arbitrary SQL code into the Metabase database, effectively giving them access to sensitive data and allowing them to manipulate application configurations. The attack can also be used to steal stored credentials for connected databases, read any data accessible through those connections, and export data.
In a statement, Metabase CEO Sameer Al-Sakran acknowledged that the company had recently been attacked by an unknown zero-day security vulnerability in versions 1.58 and above. However, he noted that customers running self-hosted instances have already received updated patches, and users of Metabase Cloud can rest assured that their instance has been updated to the latest version.
In addition to the technical details of the vulnerability, Metabase also provided a number of indicators of compromise (IoCs) for affected customers. These IoCs include a call to "POST /api/session/reset_password" with a 400 status code, followed by a call to "GET /api/user/current" with a 200 status code.
The attack has already been attributed to at least one company that was compromised, Framework, which informed all its customers that customer names, login IPs, addresses, phone numbers, and emails were accessed during the hack. Fortunately, no order or payment information was accessed.
This latest vulnerability highlights the ongoing threat of zero-day attacks in the software industry. As Metabase notes, this is not the first time the company has addressed an extremely severe flaw in its software, as it did so three years ago by addressing another "extremely severe" flaw (CVE-2023-38646) that could have resulted in pre-authenticated remote code execution on affected installations.
The incident serves as a stark reminder to organizations using Metabase and other software packages of the importance of keeping their systems up-to-date with the latest security patches. It also underscores the need for robust cybersecurity measures, such as monitoring application logs and reviewing data warehouse logs for signs of unauthorized access.
In light of this critical vulnerability, it is essential that users take immediate action to protect themselves against this attack. This includes blocking the "/api/session/reset_password" endpoint and revoking all active user sessions by accessing the Metabase Application Database and deleting all rows in the core_session table.
The latest vulnerability also raises questions about the effectiveness of existing cybersecurity measures in preventing zero-day attacks. As the threat landscape continues to evolve, it is crucial that organizations prioritize proactive security strategies, such as implementing robust monitoring systems and conducting regular security assessments.
In conclusion, the recent exploitation of a critical zero-day vulnerability in Metabase highlights the ongoing threat of software vulnerabilities to organizations worldwide. It serves as a stark reminder of the importance of keeping systems up-to-date with the latest security patches, monitoring application logs, and reviewing data warehouse logs for signs of unauthorized access.
Related Information:
https://www.ethicalhackingnews.com/articles/Metabase-Zero-Day-Exploited-in-Wild-A-Critical-Security-Flaw-Exposed-ehn.shtml
https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html
Published: Sat Aug 8 03:09:10 2026 by llama3.2 3B Q4_K_M