Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Metabase Vulnerability Allows Admin Access

Critical Metabase Vulnerability Allows Admin Access

Posted on August 9, 2026 By CWS

Metabase, a popular open-source platform for business intelligence and data visualization, has been compromised by a significant zero-day vulnerability. This flaw, identified as GHSA-vwf4-m7j8-wcjf, has been actively exploited, allowing attackers to gain full administrative control over affected systems without authentication.

Details of the Metabase Vulnerability

The vulnerability in question is an SQL injection flaw with a maximum CVSS score of 10.0, affecting versions 1.58 and later, covering branches 0.58 to 0.63. Although lacking a CVE identifier, its severity and active exploitation classify it as one of the year’s most critical vulnerabilities in business intelligence platforms.

The issue resides in the publicly accessible POST /api/session/reset_password endpoint. Attackers can inject SQL commands directly into Metabase’s database without needing to log in, enabling them to elevate their privileges to an administrator level and take control of the instance.

Impact and Exploitation

Once attackers achieve administrative access, they can modify configuration settings, extract stored database credentials, access connected data, and export sensitive information freely. The vulnerability was first exploited on August 3, when Metabase’s Cloud SaaS platform was compromised, prompting the company to block the malicious endpoints and release a patch.

While Metabase Cloud customers received an automatic update, self-hosted instances are still at risk until administrators apply the necessary patch. Data breaches have been reported by companies like Framework and Tally, resulting in unauthorized access to customer data such as names, addresses, phone numbers, and emails.

Steps for Mitigation

Administrators are urged to look for a specific attack pattern in server logs: a POST /api/session/reset_password call returning a 400 status code, followed by a GET /api/user/current call returning a 200 status code. This indicates a successful exploitation, and such instances should be treated as compromised.

Immediate upgrades to the patched versions 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5 are crucial for self-hosted Metabase. Security teams should revoke all active sessions, audit API keys, review administrator accounts for anomalies, rotate database credentials, and scrutinize query logs for unauthorized activities.

Given the central role of business intelligence tools like Metabase in organizational data ecosystems, a single SQL injection vulnerability poses a significant risk, potentially leading to widespread breaches across connected systems. Organizations should prioritize patching and assume compromise if indicative log patterns are detected.

Strengthen your security posture by integrating advanced threat detection tools to accelerate investigations and response times.

Cyber Security News Tags:admin access, business intelligence, cyber attack, Cybersecurity, data breach, data protection, data security, Metabase, Open Source, security update, software patch, SQL injection, tech news, vulnerability management, zero-day

Post navigation

Previous Post: Weekly Cybersecurity Update: Key Vulnerabilities and Exploits

Related Posts

Seedworm Exploits Signed Software for Covert Attacks Seedworm Exploits Signed Software for Covert Attacks Cyber Security News
Threat Actors Weaponizing SVG Files to Embed Malicious JavaScript Threat Actors Weaponizing SVG Files to Embed Malicious JavaScript Cyber Security News
Beware of Phishing Email from Kimusky Hackers With Subject Spetember Tax Return Due Date Notice Beware of Phishing Email from Kimusky Hackers With Subject Spetember Tax Return Due Date Notice Cyber Security News
Critical Sophos Firewall Vulnerabilities Enables pre-auth Remote Code Execution Critical Sophos Firewall Vulnerabilities Enables pre-auth Remote Code Execution Cyber Security News
Washington Post Oracle E-Suite Hack Impacts 9K+ Employees and Contractors Washington Post Oracle E-Suite Hack Impacts 9K+ Employees and Contractors Cyber Security News
Critical Vulnerabilities Found in FortiSandbox Platform Critical Vulnerabilities Found in FortiSandbox Platform Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Metabase Vulnerability Allows Admin Access
  • Weekly Cybersecurity Update: Key Vulnerabilities and Exploits
  • Enhancing Cybersecurity in Banking with Predictive Strategies
  • CSS Vulnerability Turns Emails into Keyloggers
  • Levi Strauss Faces Cyber Intrusion via Social Engineering

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Metabase Vulnerability Allows Admin Access
  • Weekly Cybersecurity Update: Key Vulnerabilities and Exploits
  • Enhancing Cybersecurity in Banking with Predictive Strategies
  • CSS Vulnerability Turns Emails into Keyloggers
  • Levi Strauss Faces Cyber Intrusion via Social Engineering

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark