<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Metabase Zero-Day Flaw Lets Attackers Seize Admin Access Without Logging In

Critical zero-day in Metabase exploited; admins urged to patch now. Unauthenticated SQL injection flaw threatens data security.
Content Team

A critical zero-day in Metabase, the popular open-source business intelligence platform, is being actively exploited in the wild. Tracked as GHSA-vwf4-m7j8-wcjf with a perfect CVSS score of 10.0, the flaw lets unauthenticated attackers inject SQL through the password reset endpoint and promote themselves to full administrator.

Metabase discovered the breach on August 3 after its own cloud platform was compromised. Cloud customers were patched automatically, but self-hosted users must upgrade manually. At least two companies — Framework and Tally — have already reported customer data theft. Admins should patch immediately and treat any instance showing the exploit's log signature as compromised.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo