Metabase Zero-Day Flaw Lets Attackers Seize Admin Access Without Logging In
Want more insights like this?
A critical zero-day in Metabase, the popular open-source business intelligence platform, is being actively exploited in the wild. Tracked as GHSA-vwf4-m7j8-wcjf with a perfect CVSS score of 10.0, the flaw lets unauthenticated attackers inject SQL through the password reset endpoint and promote themselves to full administrator.
Metabase discovered the breach on August 3 after its own cloud platform was compromised. Cloud customers were patched automatically, but self-hosted users must upgrade manually — versions 1.58 (0.58) through 0.63 are affected, with fixes in 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5. At least four companies — Framework, Tally, n8n and Kilo Code — have already reported customer data theft. Admins should patch immediately and treat any instance showing the exploit's log signature as compromised.
Source: Cybersecurity News