Particle.news

Metabase Zero-Day Used to Gain Admin Access and Steal Customer Data

The flaw lets unauthenticated attackers seize administrator control of instances, exposing stored credentials and connected databases.

Overview

  • Security teams say attackers exploited the unauthenticated vulnerability to access Metabase Cloud and self-hosted instances, with activity traced to August 3 when several customer analytics environments were accessed.
  • Metabase blocked the endpoints used in the attacks, pushed emergency patches to Metabase Cloud, and published minimum safe self-hosted releases that customers must install immediately.
  • Customers including Framework and Tally have confirmed attackers exported data from their Metabase instances and disclosed specific exposures such as names, emails, IPs, addresses, phone numbers, and password hashes.
  • Metabase advised urgent mitigations for self-hosted users: block the /api/session/reset_password endpoint if needed, upgrade to patched releases, revoke sessions, rotate database credentials, and review API keys and admin accounts.
  • Forensics and third-party investigations are ongoing and complicated by possible log tampering, raising uncertainty about the full scope of data loss and the risk to downstream vendors and their customers.