Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
- Posted on August 8, 2026
- By The Hacker News
- 0 Views
- 1 min read
In brief
Generating AI summary…
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase says a CVSS 10.0 zero-day SQL injection was exploited in the wild; the flaw can grant admin access and expose connected database data.