A critical, unpatched vulnerability in the open-source business intelligence platform Metabase has been actively exploited in the wild, granting attackers administrative access and enabling the exfiltration of sensitive organizational data. According to a report published by Security Affairs, the flaw carries a maximum CVSS score of 10. Security Affairs reported that Metabase confirmed attackers exploited the zero-day against Metabase Cloud before the company or the broader defensive community had any visibility into the flaw. Framework has publicly confirmed it was among the compromised organizations.

The incident is notable because threat actors identified and weaponized the vulnerability before any patch or public disclosure existed. Metabase acknowledged the situation and is working to secure affected environments, but the maximum severity rating indicates that immediate attention is required from all customers.

At the time of reporting, several technical details remain undisclosed. The specific CVE identifier, the exact exploitation vector, and whether self-hosted Metabase instances were also impacted have not yet been fully detailed by the vendor. The timeline between initial discovery, active exploitation, and the release of a remediation patch is also still being clarified. Organizations relying on Metabase are advised to monitor for unauthorized administrative activity and verify their deployment configurations while the investigation continues.


開源商業智能平台 Metabase 存在一個未經修補的嚴重漏洞,目前已於野外實際遭利用,賦予攻擊者管理員權限並導致敏感企業資料外洩。根據 Security Affairs 發布的報告,該漏洞的 CVSS 評分達最高級別 10 分。Security Affairs 報導指,Metabase 證實攻擊者在該公司及更廣泛的防禦社群察覺漏洞前,已利用此零日漏洞攻擊 Metabase Cloud。Framework 已公開承認其為受影響組織之一。

此次事件備受關注,因為威脅行為者在任何修補程式或公開披露之前,便已識別並武器化該漏洞。Metabase 已確認此情況並正努力修復受影響環境,但最高嚴重程度評級表明所有客戶均需立即關注。

截至報導時,部分技術細節仍未公開。具體的 CVE 識別碼、確切的利用向量,以及自建 Metabase 實例是否同樣受影響,尚未被供應商完全詳述。從最初發現、活躍利用到修補程式碼發布的時間線亦仍在釐清中。建議依賴 Metabase 的組織於調查期間持續監控未授權管理員活動,並驗證其部署配置。

新聞來源 / Original News Source