Discussion

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Started by The Hacker News · 08 Aug 2026 10:51 · 2 Views · 0 Replies
Thread Starter #0
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.

The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

Okumaya devam et...

You must be logged in to reply.

0 quotes selected