A critical zero-day vulnerability in Metabase's business intelligence software has been actively exploited, allowing unauthorized attackers to inject malicious SQL code and gain administrative access without authentication. This maximum-severity flaw, scoring 10.0 on the CVSS scale, enables remote attackers to compromise the Metabase application database, giving them unrestricted control over sensitive data1. The absence of a CVE identifier has not hindered attackers, who have already begun exploiting this vulnerability in the wild. Metabase users are advised to take immediate action to assess their exposure and apply necessary patches to prevent further compromise. The exploitation of this vulnerability highlights the importance of prompt patch management, as the window for securing systems is rapidly diminishing. So what matters to practitioners is that they must urgently evaluate their Metabase deployments to prevent potential data breaches.
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
⚠️ Critical Alert
Why This Matters
Zero-day activity targeting Meta means patching windows are already closing — assess your exposure immediately.
References
- The Hacker News. (2026, August 8). Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication. *The Hacker News*. https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html
Original Source
The Hacker News
Read original →