Metabase zero-day lets attackers take over your business data
A serious flaw in Metabase lets attackers bypass your login and take over your company's data. They can then see, change, or delete anything stored in the platform.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Not confirmed
- Affects
- Metabase
- Exploited
- Not confirmedNo confirmation recorded
How it works
An attacker sends a specially crafted request to Metabase's admin panel that tricks it into giving them full access without a password.
What to do
Check whether the installed Metabase version is older than the fixed version in the vendor advisory or current release.
Update Metabase through its normal update channel, then confirm the installed version matches the newest vendor release.
Technical details
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.