started · updated
Metabase software faces critical CVSS 10.0 zero-day exploitation
Metabase has confirmed a critical zero-day vulnerability in its business intelligence and visualization software. The flaw has been assigned a CVSS score of 10.0, indicating the highest possible severity. An unauthenticated remote attacker can inject custom SQL code into the application's database, potentially gaining administrator privileges, reading data, or altering records.
Reports indicate the vulnerability has been actively exploited since August 3. Ransomware groups, including the group known as Play, are allegedly using the flaw to encrypt systems and steal data for double extortion purposes. The Italian defense supplier Marconi Industrial Services has been listed as an alleged victim on darknet platforms. Organizations using publicly accessible Metabase instances are urged to prioritize patching and forensic investigations to identify potential unauthorized access.