Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Metabase Flaw Exploited, Urgent Patch Released

Critical Metabase Flaw Exploited, Urgent Patch Released

Posted on August 8, 2026 By CWS

Metabase has issued a warning concerning a severe security flaw within its business intelligence and data visualization software, which has been actively exploited as a zero-day vulnerability. This flaw, assigned a CVSS score of 10.0, allows remote attackers to execute unauthorized SQL commands, gaining administrator access to the application database.

Understanding the Vulnerability

The vulnerability, not yet assigned a CVE identifier, permits attackers to inject arbitrary SQL into the Metabase system. This breach facilitates unauthorized access, enabling attackers to alter configurations, steal credentials, and export data from connected databases.

In an official advisory, Metabase revealed that versions 1.58 and above of its Cloud service experienced attacks exploiting this unknown security loophole. Immediate updates have been applied to Metabase Cloud instances, and users of self-hosted versions are strongly urged to implement the latest security patches.

Affected Versions and Mitigation Steps

The affected Metabase versions range from x.58.0 to x.63.3, with fixes available starting from versions x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, and x.63.5. As an interim measure, it is recommended to block the “/api/session/reset_password” endpoint until the patch is applied.

Post-update, Metabase advises users to revoke all active sessions, inspect API keys, scrutinize administrator accounts, rotate database credentials, and monitor logs for unauthorized access.

Indicators of Compromise and Impact

While specific details of the attack remain undisclosed, Metabase has provided indicators of compromise (IoCs). A typical sign includes a “POST /api/session/reset_password” request with a 400 status code, followed by a “GET /api/user/current” with a 200 status code. If these patterns appear in logs, it may indicate a compromised system.

One notable victim, Framework, a PC manufacturer, reported a breach affecting customer data, including names, IP addresses, and contact details. However, no payment information was accessed.

Three years prior, Metabase addressed another severe flaw (CVE-2023-38646) with a CVSS score of 9.8, highlighting the ongoing challenges in securing software systems against unauthorized access.

It is imperative for Metabase users to prioritize these security updates to safeguard their systems and data from potential exploitation.

The Hacker News Tags:admin access, Cybersecurity, data breach, IT security, Metabase, patch release, security flaw, software vulnerability, SQL injection, zero-day

Post navigation

Previous Post: OpenAI Delays Astra AI Model to Address Cybersecurity Risks
Next Post: Atlassian Rovo Vulnerable to Data Exfiltration Risks

Related Posts

Tor Browser Vulnerability: A Single Webpage Visit Risk Tor Browser Vulnerability: A Single Webpage Visit Risk The Hacker News
Gitea Vulnerability Exploited in Cryptojacking Attack Gitea Vulnerability Exploited in Cryptojacking Attack The Hacker News
Unresolved Windows Search Vulnerability Risks NTLMv2 Hash Theft Unresolved Windows Search Vulnerability Risks NTLMv2 Hash Theft The Hacker News
CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials The Hacker News
Unitree G1 EDU Robots Face Critical Security Vulnerabilities Unitree G1 EDU Robots Face Critical Security Vulnerabilities The Hacker News
Linux GoGra Backdoor Targets South Asia via Microsoft API Linux GoGra Backdoor Targets South Asia via Microsoft API The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Enhancing SOC Efficiency with Threat Intelligence
  • Urgent WordPress Update Fixes Major Security Vulnerability
  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Enhancing SOC Efficiency with Threat Intelligence
  • Urgent WordPress Update Fixes Major Security Vulnerability
  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark