Home / Aug 09, 2026 / Story
0
#2 The Hacker News general August 08, 2026 at 06:58 UTC

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

By [email protected] (The Hacker News)

AI Summary

Metabase has disclosed a CVSS 10.0 zero-day vulnerability with no CVE assigned yet that allows unauthenticated remote attackers to inject arbitrary SQL into the application database, granting full admin access without credentials. Active exploitation in the wild has been confirmed, making immediate patching critical for any organization running Metabase for business intelligence or data visualization.

Relevance score: 87.0/100

# More from August 09