Summary
A critical zero-day vulnerability in Metabase, the popular open-source data analytics platform, is being actively exploited in the wild to gain administrative access without authentication. The vulnerability, assigned a maximum CVSS score of 10.0, allows unauthenticated remote attackers to inject SQL queries directly into Metabase\u2019s internal database, effectively giving them full administrative control over any instance that processes user-submitted queries.
Framework Tally, the security firm that disclosed the vulnerability, confirmed that customer data theft has already been observed in the wild. The flaw has no CVE identifier yet, which means organizations using Metabase may not have received patch notifications from their vendors. The vulnerability affects Metabase versions running the SQL query engine that processes user-generated analytics queries, making any instance that accepts user-generated queries potentially vulnerable.
Source: BleepingComputer
Why This Matters
Metabase is widely deployed across organizations of all sizes as a self-service analytics tool. Its popularity stems from its ease of use \u2014 business analysts can build dashboards and run queries without writing SQL. But that same design makes it a perfect attack surface: any user who can access the Metabase interface can potentially submit crafted queries that exploit the zero-day. The fact that exploitation is already producing data theft confirms this is not a theoretical risk.
Who is impacted: All organizations running Metabase instances that accept user-generated queries. This includes startups, enterprises, government agencies, and research institutions that use Metabase for customer data visualization and business intelligence.
Actionable steps: Immediately restrict Metabase access to authenticated users only, disable any public sharing features, and apply the latest patch from Metabase. If no patch is available, disable the query execution feature entirely until one is released. Organizations should also audit Metabase logs for any suspicious query patterns that may indicate active exploitation.
