hacker-news · Crawled Aug 8, 2026

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

2 IoCs 1 CVEs
Read original article ↗

AI Summary

A zero-day vulnerability in Metabase versions 1.58 and above is being actively exploited in the wild, allowing unauthenticated attackers to gain administrator access by injecting arbitrary SQL into the application database. The attack chain involves sending a POST request to '/api/session/reset_password' followed by a GET to '/api/user/current', which can be detected in logs as an indicator of compromise. Metabase Cloud instances have been patched, but self-hosted users are urged to update immediately. The PC maker Framework confirmed customer data was accessed, including names, IPs, addresses, phone numbers, and emails, though no payment data was involved.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
Filename /api/session/reset_password Details →
Filename /api/user/current Details →