A critical zero-day vulnerability in the widely used Metabase business intelligence platform is being actively exploited in the wild, allowing unauthenticated remote attackers to gain complete administrative control over affected deployments. Metabase has issued an emergency security advisory urging immediate action, classifying the flaw with a maximum CVSS score of 10.0.

The vulnerability permits attackers to bypass all authentication and inject arbitrary SQL commands directly into the Metabase application database. No credentials, prior access, or user interaction is required to trigger the flaw. According to the disclosure, threat actors began leveraging this weakness before a patch was available, confirming its status as an actively exploited zero-day. Notably, the vulnerability has not yet been assigned a CVE identifier, a gap that is complicating automated detection and enterprise tracking workflows that rely on standardized naming conventions.

Both the open-source and commercial Metabase Pro editions are affected. Metabase has released patched versions and is urging all administrators to upgrade immediately. Organizations that cannot patch right away should take internet-facing instances offline or implement strict network-level access controls as a temporary mitigation.

Given that Metabase typically serves as a central hub connecting to critical production databases, customer records, and financial systems, the potential fallout from a successful compromise is severe. Attackers could leverage a breached instance to exfiltrate sensitive datasets, move laterally across internal networks, or manipulate business intelligence outputs to conceal malicious activity.

Security teams should treat this as a critical incident response priority. Beyond applying the vendor's patches, administrators should immediately audit application and access logs for signs of compromise, such as unusual queries, unrecognized administrative actions, or connections from suspicious IP addresses. Strict network segmentation around Metabase services is strongly recommended to contain potential lateral movement, and credential rotation for all connected databases should be performed as a precautionary measure.

The incident also underscores the importance of configuring analytics platforms with the principle of least privilege, granting only the minimum database permissions necessary. This limits the blast radius should a platform like Metabase be compromised. Organizations should monitor the vendor's advisory for the eventual publication of a CVE identifier, but should not delay action while waiting for it. Proactive patching, log review, and network isolation remain the most reliable defenses against this active threat.


一個影響廣泛的 Metabase 商業智能平台的嚴重零日漏洞正於野外被積極利用,允許未經驗證的遠端攻擊者取得對受影響部署方案的完整管理員控制權。Metabase 已發布緊急安全公告,敦促立即採取行動,並將此漏洞列為 CVSS 最高評分 10.0。

該漏洞允許攻擊者繞過所有認證,並直接向 Metabase 應用程式數據庫注入任意 SQL 指令。無需憑證、預先存取或用戶互動即可觸發此漏洞。根據披露資料,威脅行為者早在補丁發布前就已利用此弱點,證實其為一個已被積極利用的零日漏洞。值得注意的是,該漏洞尚未被分配 CVE 編號,這一缺失正複雜化依賴標準命名慣例的自動化偵測及企業追蹤工作流程。

開源版本及商業版 Metabase Pro 均受影響。Metabase 已發布修補版本,並敦促所有管理員立即升級。無法立即修補的組織,應將面向互聯網的實例下線或實施嚴格的網絡層級存取控制作為臨時緩解措施。

鑒於 Metabase 通常作為連接關鍵生產數據庫、客戶記錄及財務系統的核心樞紐,一次成功的入侵可能造成嚴重後果。攻擊者可利用遭入侵的實例竊取敏感數據集、在內部網絡進行橫向移動,或篡改業務智能輸出以隱匿惡意活動。

安全團隊應將此視為優先級別最高的事件響應。除了套用供應商的補丁外,管理員應立即審計應用程式及存取日誌以尋找入侵跡象,例如異常查詢、未識別的管理操作或來自可疑 IP 地址的連線。強烈建議在 Metabase 服務周邊實施嚴格的網絡分隔,以控制潛在的橫向移動,並作為預防措施,應輪換所有連接數據庫的憑證。

此事件亦突顯了以最低權限原則配置分析平台的重要性,僅授予必要的最低數據庫權限。這能限制如 Metabase 等平台遭入侵時的影響範圍。組織應關注供應商公告以獲取 CVE 編號的最終發布,但不應在等待期間延遲行動。主動打補丁、日誌審查及網絡隔離,仍是對抗此活躍威脅最可靠的防禦手段。

新聞來源 / Original News Source