Back to all news
Security

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

The Hacker News·August 8, 2026·1 min read
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase warned of a maximum-severity zero-day vulnerability (CVSS 10.0) in its business intelligence software being exploited in the wild. The flaw allows unauthenticated remote attackers to inject arbitrary SQL into the application database, enabling admin access. No CVE identifier has been assigned yet. Users are urged to apply patches immediately.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store