DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

Metabase on 116,913 observed hosts: business intelligence as an unguarded data path

The number

A ZoomEye query for app="Metabase" returned 116,913 matching hosts, collected on 2 October 2026 with sub_type=all and a page size of one. The count is the fingerprint match total. Business intelligence platforms appear in large numbers because they are easy to deploy and often land on a shared host with a memorable address.

Metabase connects to databases with a stored connection, and the questions and dashboards it renders are SQL that runs against those databases. The application is therefore an authenticated proxy to every connected data source.

What the surface exposes

An installation that has completed first-run setup presents a login. An installation that has not presents a setup page that creates the first administrator, which is the case worth searching for because it converts an exposed instance into full control of the connected databases.

Beyond that, the public sharing feature allows a question or dashboard to be published at a link without authentication, and the feature is enabled by default unless it has been turned off. A shared link reveals whatever the underlying query returns, including data the sharing administrator may not have considered sensitive when the link was created.

What the count does not say

116,913 hosts identify as Metabase. It does not say how many have completed setup, how many have public sharing enabled, or how many databases each can reach. Those are per-instance facts, and they are exactly the facts a defender should collect internally rather than infer from a scan.

Why the exposure matters

The platform concentrates database credentials in one place and presents them through an interface designed for ease of use. Database connections are frequently created with administrative or read-all accounts because that is the path of least resistance during a trial. A single account takeover therefore reads any table the connected account can read, and the list of connected accounts is visible in the interface.

What to do

Disable public sharing where it is not required, and review existing share links for content that has changed meaning since publication. Review the database connections and replace broad accounts with roles limited to the tables the platform actually serves.

Require authentication through the platform or an upstream proxy, keep the instance on an internal network, and check whether the setup flow has been completed on every deployment rather than only the primary one. Where several copies exist for testing, treat them as in scope, because a test copy usually carries a copy of the production connection.

References

  1. Metabase documentation. https://www.metabase.com/docs/latest/
  2. ZoomEye. https://www.zoomeye.ai/

Top comments (0)