Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.

The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests

29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests A heap over-read in the Squid web proxy can leak another user’s cleartext HTTP request, including any credentials or session

Document-borne AI worms can self-propagate through Copilot for Word

Document-borne AI worms can self-propagate through Copilot for Word Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 18.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 74.7.227.2 — 1146 requests (recent log) 213.209.159.175 — 263 requests (recent log) 89.167.35.212 — 120 requests (recent