Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has disclosed that a maximum-severity zero-day in its business intelligence and data visualization software was exploited in the wild, allowing unauthenticated attackers to inject SQL and gain administrator access. The issue affected Metabase Cloud and self-hosted versions, with Framework confirming customer data exposure, while Metabase urged immediate patching and log review. #Metabase #Framework #SameerAlSakran

Keypoints

  • Metabase confirmed a CVSS 10.0 zero-day was exploited in the wild.
  • The flaw allowed unauthenticated SQL injection and administrator takeover.
  • Affected users were advised to patch immediately and block /api/session/reset_password.
  • Metabase provided indicators of compromise involving specific API request patterns.
  • Framework reported exposure of customer names, IPs, addresses, phone numbers, and emails.

Read More: https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html