hacker-news · Crawled Aug 8, 2026
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
2 IoCs 1 CVEs
Read original article ↗
AI Summary
A zero-day vulnerability in Metabase versions 1.58 and above is being actively exploited in the wild, allowing unauthenticated attackers to gain administrator access by injecting arbitrary SQL into the application database. The attack chain involves sending a POST request to '/api/session/reset_password' followed by a GET to '/api/user/current', which can be detected in logs as an indicator of compromise. Metabase Cloud instances have been patched, but self-hosted users are urged to update immediately. The PC maker Framework confirmed customer data was accessed, including names, IPs, addresses, phone numbers, and emails, though no payment data was involved.
AI-extracted · verify before operational use