Metabase Zero-Day Flaw Lets Attackers Seize Admin Access Without Logging In
Critical zero-day in Metabase exploited; admins urged to patch now. Unauthenticated SQL injection flaw threatens data security.
By
Content Team
ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
A critical zero-day in Metabase, the popular open-source business intelligence platform, is being actively exploited in the wild. Tracked as GHSA-vwf4-m7j8-wcjf with a perfect CVSS score of 10.0, the flaw lets unauthenticated attackers inject SQL through the password reset endpoint and promote themselves to full administrator.
Metabase discovered the breach on August 3 after its own cloud platform was compromised. Cloud customers were patched automatically, but self-hosted users must upgrade manually. At least two companies — Framework and Tally — have already reported customer data theft. Admins should patch immediately and treat any instance showing the exploit's log signature as compromised.
Source: Cybersecurity News
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo