CyberSecurity News
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
AI summary
A critical security flaw in Metabase's business intelligence and data visualization software has been exploited as a zero-day, allowing unauthorized access. The vulnerability enables an unauthenticated remote attacker to inject arbitrary SQL into the application database. This allows attackers to gain administrative access without authentication. The flaw has a maximum CVSS score of 10.0, indicating a high level of severity. Metabase has issued a warning about the vulnerability, which currently does not have a CVE identifier assigned to it.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

