Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
A high-severity vulnerability affecting Metabase’s data visualization and business intelligence software has been actively exploited in attacks targeting unpatched systems. The flaw, rated with a CVSS score of 10.0, enables attackers to inject arbitrary SQL queries into the application database, granting them full administrative control without needing to authenticate. Attackers can then modify configurations, extract credentials, access sensitive data, or export files from connected databases. Metabase Cloud is already updated, but users running self-hosted instances should apply the latest patches right away. Affected versions include multiple ranges from x.58.0 up to certain points before fixes were introduced. As a temporary measure, blocking the "/api/session/reset_password" endpoint is recommended until updates are applied.