CyberNews
← Back to dashboard
NEWS The Hacker News

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Aug 8, 2026, 06:58 AM · by The Hacker News

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

Security research like this is a reminder that visibility into endpoints, identity, and network traffic remains the foundation of any effective defense program.

Security teams should review their detection rules, keep threat-intelligence feeds current, and validate that incident-response runbooks are tested before an incident occurs.

Source: The Hacker News