logo

Critical Metabase Zero-Day Exploited

ID: ecf3b382-bf7c-5cc0-b55f-a2686c473bd1

STIX ID: report--ecf3b382-bf7c-5cc0-b55f-a2686c473bd1

Feed Name: SOCRadar Blog

Threat Score
95/100

Date Published: 2026-08-10

Date Updated: 2026-08-11

Author: ameer

...
...

Metabase disclosed a critical CVSS 10.0 zero-day SQL injection in an unauthenticated password-reset endpoint (/api/session/reset_password) that is being actively exploited; self-hosted, internet-exposed instances are at highest risk because successful exploitation can yield administrative control and access to stored database credentials and data. The vendor lists affected x.58–x.63 branches and published fixed releases, recommends immediate upgrading (or temporarily blocking the endpoint), revoking sessions, rotating connected database credentials, and reviewing logs and query history; a behavioral detection sequence (POST to /api/session/reset_password returning 400 followed by GET /api/user/current returning 200) is provided for investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.