CVE Tools

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

The Hacker NewsBy The Hacker News

Reported exploitedMetabase

Our summary

A high-severity vulnerability affecting Metabase’s data visualization and business intelligence software has been actively exploited in attacks targeting unpatched systems. The flaw, rated with a CVSS score of 10.0, enables attackers to inject arbitrary SQL queries into the application database, granting them full administrative control without needing to authenticate. Attackers can then modify configurations, extract credentials, access sensitive data, or export files from connected databases. Metabase Cloud is already updated, but users running self-hosted instances should apply the latest patches right away. Affected versions include multiple ranges from x.58.0 up to certain points before fixes were introduced. As a temporary measure, blocking the "/api/session/reset_password" endpoint is recommended until updates are applied.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store