#2
The Hacker News
general
August 08, 2026 at 06:58 UTC
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
By [email protected] (The Hacker News)
AI Summary
Metabase has disclosed a CVSS 10.0 zero-day vulnerability with no CVE assigned yet that allows unauthenticated remote attackers to inject arbitrary SQL into the application database, granting full admin access without credentials. Active exploitation in the wild has been confirmed, making immediate patching critical for any organization running Metabase for business intelligence or data visualization.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →