Utopia Tech
SecurityAI-assisted1 min read

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has disclosed a critical zero-day vulnerability with a maximum CVSS score of 10.0 in its business intelligence platform that is being actively exploited in the wild. The flaw allows unauthenticated remote attackers to execute arbitrary SQL injection attacks against the Metabase application database, potentially granting unauthorized administrative access without any authentication require

UT

Utopia Tech

August 8, 2026 · 1 min read

Share

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content