A critical zero-day in Metabase, the popular open-source business intelligence platform, is being actively exploited in the wild. Tracked as GHSA-vwf4-m7j8-wcjf with a perfect CVSS score of 10.0, the flaw lets unauthenticated attackers inject SQL through the password reset endpoint and promote themselves to full administrator.
Metabase discovered the breach on August 3 after its own cloud platform was compromised. Cloud customers were patched automatically, but self-hosted users must upgrade manually. At least two companies — Framework and Tally — have already reported customer data theft. Admins should patch immediately and treat any instance showing the exploit's log signature as compromised.
Source: Cybersecurity News