Metabase has confirmed that a maximum severity security vulnerability affecting its business intelligence and data visualization platform has been actively exploited as a zero day, prompting the company to release security updates for affected versions. According to Metabase, the vulnerability allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, resulting in administrator level access to vulnerable instances. Once administrator privileges are obtained, an attacker can modify application settings, access stored credentials for connected databases, read information available through those database connections, and export data from affected environments. The issue carries a CVSS severity score of 10.0, although it has not been assigned a CVE identifier. Metabase disclosed that the attacks targeted Metabase Cloud environments running version 1.58 and later before the vulnerability became publicly known, confirming that the flaw had been exploited as a zero day before security updates were released.
According to the company, all Metabase Cloud deployments have already been updated to protected versions, while organizations operating self hosted installations have been advised to install the latest security patches immediately. The affected software versions include releases beginning with version 1.58 through multiple supported release branches. Security fixes have been issued in versions x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, and x.63.5. Until updates can be applied, Metabase recommends temporarily blocking access to the /api/session/reset_password endpoint to reduce exposure. After installing the security updates, organizations with publicly accessible password reset endpoints have also been advised to invalidate all active user sessions by deleting records from the core_session table within the application database. Additional recommendations include reviewing API keys for unexpected entries, verifying administrator accounts for unauthorized changes, rotating credentials used for connected databases, examining data warehouse logs for unusual activity, and reviewing Metabase activity logs together with query history for signs of unauthorized access. These measures are intended to help organizations determine whether attackers successfully obtained administrator privileges before the security updates were installed.
Metabase has not disclosed technical details regarding the attacks or identified those responsible for exploiting the vulnerability, but it has published indicators of compromise to assist administrators with incident response activities. According to Metabase Chief Executive Officer Sameer Al Sakran, administrators should review application logs and server ingress logs for a POST /api/session/reset_password request returning a 400 response, immediately followed by a GET /api/user/current request returning a 200 response. The company stated that this sequence strongly indicates that a vulnerable instance may have been compromised through the newly disclosed attack method. Administrators detecting these indicators have been encouraged to treat the incident as a likely compromise and proceed with credential rotation, account validation, and detailed forensic review of affected environments. Metabase has not provided additional information regarding the number of organizations affected or the duration of the attacks before discovery.
One confirmed victim identified following the disclosure is Framework, the computer manufacturer, which informed customers that personal information including customer names, email addresses, telephone numbers, physical addresses, and login IP addresses had been accessed during the incident. According to the company’s notification, payment information and order details were not exposed. The latest security issue follows another serious Metabase vulnerability disclosed three years earlier. In 2023, the company addressed CVE 2023 38646, a critical vulnerability with a CVSS score of 9.8 that could allow pre authentication remote code execution on affected installations. The latest incident highlights the importance of applying security updates promptly, monitoring authentication activity, reviewing administrative access, and validating database credentials following confirmation that the vulnerability has already been exploited against real world deployments before patches became available.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





