AI Stories on SHORT INFO are generated & curated with AI
unverified 10 Aug, 09:10

Metabase zero-day CVSS 10.0 SQL injection actively exploited, self-hosted instances exposed

Every self-hosted Metabase instance on an unpatched version is exposed to a maximum-severity zero-day right now. The CVSS 10.0 flaw sits in the password-reset endpoint and lets attackers become admin without logging in, then steal database credentials, per BleepingComputer.

A maximum-severity zero-day vulnerability in Metabase, the widely used business intelligence platform, is leaving every unpatched self-hosted instance exposed to unauthenticated admin takeover right now. The flaw, rated CVSS 10.0, is a SQL injection bug in the password-reset endpoint that lets an attacker inject arbitrary database commands without logging in, escalate straight to administrator access, steal stored database credentials, and export whatever data those credentials connect to, according to BleepingComputer. Metabase discovered the issue after its own Cloud platform was breached on August 3. Confirmed victims of the campaign include Framework and Tally. Metabase Cloud customers have already been automatically patched. But the flaw affects every release from version 1.58 onward, across branches 0.58 through 0.63, and any self-hosted deployment stays vulnerable until an administrator manually installs the fix. For any organization running its own business intelligence stack, this is not a future risk. It is an open door today.

Published on
XBlueskyFacebookThreads