Metabase cloud hit first in CVSS 10 zero-day campaign

Attackers used an unknown Metabase flaw to grab admin access and customer data before a patch shipped.

CSBadmin
2 Min Read

Metabase disclosed that attackers used an unknown, maximum-severity flaw against its cloud service before any fix existed. The company’s advisory says the bug carries a CVSS score of 10.0 and lets an unauthenticated attacker inject arbitrary SQL into the Metabase application database, then seize administrator rights.

With admin access, intruders can change application configuration, steal stored credentials for connected databases, read any data those connections reach, and export it. The affected range spans versions 58 through 63, with patches at 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5. Until an upgrade lands, Metabase recommends blocking the /api/session/reset_password endpoint at the network level.

PC maker Framework confirmed it was hit through the flaw, saying names, login IPs, addresses, phone numbers, and email addresses were accessed. It said no order or payment information was touched.

Metabase published a compromise signature for log hunting: a POST to /api/session/reset_password returning 400, followed by a GET to /api/user/current returning 200. Anyone who sees that sequence should treat the instance as breached. The cleanup list includes clearing the core_session table, auditing API keys and administrator accounts, and rotating credentials on every connected database.

The uncomfortable detail is the timeline: real attackers found the flaw before Metabase did, and the company learned of it only because its own cloud was targeted. Self-hosted instances on versions 1.58 and above should be treated as urgent, not routine.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.