Code Defence Cyber security

Critical Metabase SQL injection zero day exploited in corporate data theft attacks

Active zero day exploitation targeting a leading open source business intelligence and analytics platform has been uncovered, with threat actors extracting sensitive database content from cloud and self-hosted deployments. The vulnerability allows unauthenticated remote actors to submit malformed API requests to gain full administrative rights over the reporting platform.

The security issue impacts Metabase installations running version 1.58 and later builds. Threat telemetry confirms that external actors utilized unauthenticated SQL injection vectors to bypass session verification gates, gain administrative session tokens, and access connected database schemas. Once administrative access is established, the attackers execute custom database export queries to exfiltrate proprietary financial reports, customer metrics, and internal analytics repositories.

Subverting central business intelligence platforms presents immediate enterprise privacy and compliance risks. Because analytics dashboards consolidate database credentials, API connection strings, and sensitive business intelligence datasets, an unauthenticated administrative compromise grants adversaries access to core database infrastructure and corporate intellectual property.

– Upgrade self-hosted Metabase instances immediately to patched version builds published by Metabase.

– Inspect application web server access logs for anomalous SQL injection strings or unauthorized administrative API calls.

– Audit database access logs for large, unexpected bulk exports originating from business intelligence service accounts.

– Rotate all database credentials and API tokens stored within Metabase application settings.

Business intelligence software security relies on strict database parameterization and prompt zero day patch deployment to ensure corporate reporting tools remain completely insulated from unauthenticated SQL injection. #CodeDefence #Metabase #SQLi #ZeroDay #DataTheft #AppSec #VulnerabilityManagement
/

Scroll to Top