2026-08-09HIGHexploitedMetabase Cloud was breached through its own 0-day; self-hosted instances stay vulnerable until manually upgraded
Dire Wolf
actor · actor:dire-wolf
Ransomware and data-extortion group. VenariX reports it exploited the Metabase SQL-injection zero-day CVE-2026-72898 against self-hosted instances in at least two incidents (Statista, Dodo Payments) and suspects fourteen more targets; VenariX has no evidence the group discovered the flaw or is behind the other Metabase incidents.
Coverage
1
first 2026-08-09 → last 2026-08-09
Latest activity
2026-09-29
Metabase Cloud was breached through its own 0-day; self-hosted instances stay vulnerable until manually…
Peak priority
high
1 high
Targets
technology
sectors: technology, public-sector, finance · regions: europe
Sources cited
10
10 hosts
Action items (2)
Do-now tasks recorded on the entries about Dire Wolf, newest first. Check the date before acting on an older one.
- Upgrade every self-hosted Metabase to at least 0.58.24 / 0.59.21 / 0.60.17 / 0.61.11 / 0.62.9 / 0.63.5, then, for any instance that was reachable and unpatched during the exploitation window, revoke all active sessions by clearing the core_session table, delete unrecognised API keys, and rotate the credentials for every connected database and warehouse, not just the Metabase admin credentials, because the upgrade does not invalidate what was already retrieved.2026-08-09CVE-2026-72898
- Search Metabase application or reverse-proxy ingress logs across the entire pre-upgrade exposure window for a POST to /api/session/reset_password returning HTTP 400 immediately followed by a GET to /api/user/current returning HTTP 200 from the same source; Metabase states that sequence indicates the instance was likely compromised.2026-08-09CVE-2026-72898
Defender insights
What each entry about Dire Wolf tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (5 across 6 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts · Exploit Public-Facing Application
- PersistenceValid Accounts
- Privilege EscalationValid Accounts
- StealthValid Accounts
- Credential AccessUnsecured Credentials · Unsecured Credentials: Credentials In Files
- CollectionData from Information Repositories
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗
Stealth TA0005
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗
Credential Access TA0006
T1552Unsecured Credentials×1
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗
T1552.001Unsecured Credentials: Credentials In Files×1
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗
Collection TA0009
T1213Data from Information Repositories×1
Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).
Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗
Entries about Dire Wolf (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Metabase×1
- Metabase Cloud×1
- Metabase unauthenticated SQL injection via the /api/session/reset_password endpoint reaching administrator access, CVSS 10.0; the identifier assigned in GHSA-vwf4-m7j8-wcjf for the zero-day Metabase confirmed was already being exploited, CISA KEV 2026-08-11.×1
- Metabase unauthenticated SQL-injection zero-day exploitation (August 2026)×1
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (10%)
- cisa.gov1 (10%)
- cyberattaque.org1 (10%)
- databreaches.net1 (10%)
- dodopayments.com1 (10%)
- frenchbreaches.com1 (10%)
- github.com1 (10%)
- medianama.com1 (10%)
- other2 (20%)
All cited sources (10)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
- cisa.govCISAhttps://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
- cyberattaque.orgCyberattaque.orghttps://www.cyberattaque.org/carrefour-des-donnees-clients-exposees-apres-la-cyberattaque-de-son-prestataire/
- databreaches.netDataBreaches.nethttps://databreaches.net/2026/08/17/israels-largest-crypto-broker-bits-of-gold-hit-by-data-breach-affecting-200000-customers/
- dodopayments.comDodo Paymentshttps://dodopayments.com/blogs/security-incident-internal-analytics-system
- frenchbreaches.comFrench Breacheshttps://frenchbreaches.com/alertes/carrefour-shipup-muixw7rd535cstgrh65
- github.comMetabase (GitHub Security Advisory)https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
- medianama.comMediaNamahttps://www.medianama.com/2026/09/223-dark-web-dodo-data-breach/
- metabase.comMetabasehttps://www.metabase.com/blog/security-update
- venarix.comVenariXhttps://venarix.com/blog/metabase-security-incident-downstream-impact-across-customer-environments