Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Summary

Metabase has issued a warning about a critical zero-day vulnerability in its business intelligence software. This flaw has reportedly been exploited in the wild and allows unauthenticated attackers to inject SQL and gain administrative access.

IFF Assessment

FOE

This vulnerability allows unauthenticated attackers to gain administrative access, posing a significant threat to data security and organizational control.

Severity

10.0 Critical

The vulnerability has a maximum severity score of 10.0, indicating a critical flaw that allows unauthenticated remote attackers to inject arbitrary SQL, leading to complete administrative control over the Metabase application database.

Defender Context

Defenders should prioritize patching or mitigating this vulnerability in Metabase instances immediately, given its exploitation in the wild and critical impact. This highlights the ongoing risk of zero-day exploits in widely used business intelligence tools and the importance of prompt vendor responses and security updates.

Read Full Story →