LIVE · cybersecurity feed
Live wire
CVE-2023-38646critical

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has issued a critical alert regarding a zero-day vulnerability in its business intelligence software that has been actively exploited. The flaw allows unauthenticated attackers to inject SQL, leading to administrator access, credential theft, and data exfiltration. Metabase Cloud instances have been patched, and users of self-hosted versions are urged to update immediately.

zeroday.news ·

Metabase has issued a critical alert regarding a zero-day vulnerability in its business intelligence software that is actively being exploited in the wild. The flaw reportedly allows unauthenticated attackers to achieve administrator access, facilitating credential theft and data exfiltration. Metabase Cloud instances have been patched, and self-hosted users are urged to update their installations immediately.

The vulnerability is described as an SQL injection flaw. This class of vulnerability typically arises when an application constructs SQL queries using unsanitized user-supplied input. An attacker can then inject malicious SQL code into the input fields, which the database server executes. In this specific case, the successful injection reportedly grants the attacker administrator-level access to the Metabase instance.

With administrator access, an attacker would likely gain full control over the Metabase application. This level of access commonly allows for the manipulation of data sources, the creation or modification of user accounts, and the ability to view or export sensitive information managed by the business intelligence platform. The report specifically mentions credential theft and data exfiltration as potential consequences.

Metabase is a popular open-source business intelligence tool that allows organizations to create dashboards, charts, and reports from various data sources. Its widespread use across different industries means that a critical vulnerability like this could have a significant impact on organizations that rely on it for data analysis and reporting. The ease of exploitation, requiring no authentication, further elevates the risk.

The vendor has taken swift action, patching all Metabase Cloud instances to mitigate the threat. For self-hosted deployments, users are responsible for applying the necessary updates. Organizations running self-hosted Metabase instances are advised to prioritize this update, as the active exploitation in the wild indicates an immediate threat.

Mitigation for this type of vulnerability typically involves applying vendor-supplied patches, which address the specific flaw by correctly sanitizing or parameterizing SQL queries. Beyond patching, organizations are generally advised to follow security best practices, such as network segmentation to limit access to critical applications, implementing strong authentication mechanisms, and regularly auditing logs for suspicious activity.

This incident underscores the persistent threat posed by zero-day vulnerabilities, particularly those that enable unauthenticated access to critical systems. The rapid exploitation of such flaws highlights the importance of timely patching and robust security hygiene for all software, especially business intelligence platforms that often handle sensitive organizational data.

metabasezero-dayvulnerabilitysql injectiondata breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

surveillance

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety, a company known for its public safety cameras, reportedly pitched a plan to utilize dashcams from rideshare and delivery vehicles to collect license plate data. This initiative, which did not proceed, would have involved a partnership with Nexar, a dashcam manufacturer, and potentially involved drivers without their knowledge. Separately, a former Flock employee alleged the company provided direct camera access to ICE and CBP through a pilot program, contradicting internal statements.

email securityhigh

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.

css attackshigh

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New research reveals that sophisticated CSS-based attacks can bypass webmail security measures, enabling attackers to steal sensitive information like passwords and session tokens. These techniques exploit vulnerabilities in popular email services including Outlook, Gmail, and Yahoo Mail, potentially leading to account takeovers and data breaches. The findings highlight the need for stricter sanitization and isolation of email content.

breach

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered […]