Skip to content
Threat Feed
critical advisory

Critical SQL Injection and Privilege Escalation Vulnerability in Metabase

An unauthenticated remote attacker can exploit a vulnerability in Metabase to perform SQL injection and escalate privileges.

Metabase contains a critical security vulnerability that allows an unauthenticated remote attacker to execute SQL injection attacks and achieve privilege escalation within the application. This flaw poses a significant risk to data confidentiality and integrity, as successful exploitation provides unauthorized access to database contents and administrative functions. Defenders should prioritize patching or restricting access to the Metabase instance until remediation is applied.

Impact

Successful exploitation results in full database compromise and unauthorized administrative control over the Metabase instance. This facilitates the extraction of sensitive information, modification of data, and persistent access to backend systems connected via the reporting tool.

Recommendation

  • Immediately update Metabase instances to the latest version provided by the vendor.
  • Restrict access to the Metabase interface to trusted networks only until patches are deployed.
  • Review database audit logs for anomalous SQL queries originating from the Metabase service account.

Immediate actions

Patch Metabase to the latest available vendor version

IT Operations 24h

Mitigations

Restrict network access to Metabase via firewall rules

immediate IT Operations

Public-facing application exploitation