Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
ID: 10060941-7ad7-5fe8-b286-d471218d432c
STIX ID: report--10060941-7ad7-5fe8-b286-d471218d432c
Feed Name: Security Affairs
Metabase disclosed a CVSS 10.0 zero-day that was exploited in the wild allowing unauthenticated attackers to inject arbitrary SQL into the application database, gain admin access, steal stored database credentials, and exfiltrate data. The flaw affected Metabase branches 0.58–0.63 (specific patched point releases listed), was observed against Metabase Cloud (with at least one confirmed victim, Framework), and includes an IOC: a POST to /api/session/reset_password (400) followed by GET /api/user/current (200). Metabase mitigated the cloud impact, published patches and a temporary network-block recommendation, and advised self-hosted users to treat instances showing the IOC as breached and to rotate credentials, clear sessions, and audit access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
