Post
CRITICAL ⚡ MUST-KNOW

Metabase Zero-Day Under Active Exploitation Grants Unauthenticated Admin Access

· zero-day · sqli · vulnerability

Metabase has confirmed that a maximum-severity flaw (CVSS 10.0) in its business intelligence and data visualization software is being actively exploited in the wild as a zero-day. The bug has no assigned CVE identifier. It allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can be leveraged to gain administrative access without credentials. Organizations running self-hosted Metabase instances should treat this as urgent, apply vendor guidance as soon as it’s available, and review logs for signs of unauthorized admin access.