Metabase Zero-Day (CVSS 10.0) Actively Exploited — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Metabase disclosed a CVSS 10.0 zero-day (no CVE assigned) in versions 1.58 and above that lets unauthenticated remote attackers inject arbitrary SQL into the application database and gain administrator access
- With elevated access, attackers can change application configuration, steal credentials for connected databases, read any data accessible through those connections, and export data
- Metabase Cloud was actively attacked via the flaw; cloud instances are already patched, while self-hosted users across six version branches — x.58 through x.63 — must apply updates immediately (e.g., x.58.0–x.58.23 fixed in x.58.24)
- As a temporary workaround, Metabase advises blocking the "/api/session/reset_password" endpoint, and provided IoCs: a POST to that endpoint returning 400 followed by a GET to /api/user/current returning 200
- Framework, the PC maker, confirmed customer names, login IPs, addresses, phone numbers, and emails were accessed during the attack, though no order or payment information was compromised
- Post-update, Metabase instructs users to revoke all active sessions, review and delete unrecognized API keys, audit administrator accounts, rotate connected database credentials, and review data warehouse and query history for unauthorized activity
Why it matters: Self-hosted Metabase administrators running versions x.58 through x.63 face an immediate patching window — the exploit requires no credentials and the IoC pattern (a 400 followed by a 200 on specific session endpoints) is trivially searchable in access logs. Framework's confirmed breach, with customer names, addresses, and contact data exposed, demonstrates the exploit chain works end-to-end against production deployments.
Ask SkimNews




