Critical Metabase Zero-Day Exploited in Widespread Data Theft Campaign

A critical zero-day SQL injection vulnerability in Metabase allows unauthenticated attackers to gain administrator access to customer instances, enabling data theft and credential stealing. The flaw carries a maximum CVSS score of 10.0 and affects versions 1.58 and above. Both Metabase Cloud and self-hosted installations are vulnerable, with Framework and Tally confirmed as impacted customers.

The vulnerability lets remote attackers inject arbitrary SQL into the Metabase application database, giving them full administrative control. From there, attackers change application configurations, steal stored credentials for connected databases, read accessible data, and export sensitive information. Metabase confirms active exploitation and has already blocked the compromised endpoints and patched its Cloud platform.

Self-hosted customers must manually update to safe versions, which include releases 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5. Organizations unable to upgrade immediately should block access to the /api/session/reset_password endpoint as a temporary measure. Metabase also advises all self-hosted users to revoke active sessions and review API keys following the update.

Read More at the original source →