HackerFeeds

CyberSecurity News

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

The Hacker News
· August 8, 2026

AI summary

A critical security flaw in Metabase's business intelligence and data visualization software has been exploited as a zero-day, allowing unauthorized access. The vulnerability enables an unauthenticated remote attacker to inject arbitrary SQL into the application database. This allows attackers to gain administrative access without authentication. The flaw has a maximum CVSS score of 10.0, indicating a high level of severity. Metabase has issued a warning about the vulnerability, which currently does not have a CVE identifier assigned to it.

Read the full article at The Hacker Newsthehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.