logo

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

ID: 10060941-7ad7-5fe8-b286-d471218d432c

STIX ID: report--10060941-7ad7-5fe8-b286-d471218d432c

Feed Name: Security Affairs

Threat Score
95/100

Date Published: 2026-08-08

Date Updated: 2026-08-10

Author: Pierluigi Paganini

...
...

Metabase disclosed a CVSS 10.0 zero-day that was exploited in the wild allowing unauthenticated attackers to inject arbitrary SQL into the application database, gain admin access, steal stored database credentials, and exfiltrate data. The flaw affected Metabase branches 0.58–0.63 (specific patched point releases listed), was observed against Metabase Cloud (with at least one confirmed victim, Framework), and includes an IOC: a POST to /api/session/reset_password (400) followed by GET /api/user/current (200). Metabase mitigated the cloud impact, published patches and a temporary network-block recommendation, and advised self-hosted users to treat instances showing the IOC as breached and to rotate credentials, clear sessions, and audit access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.