Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.

The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Norway imposes near ban on AI in elementary school

Norway imposes near ban on AI in elementary school Source: Hacker News

The Australian Government to Require SMS/MMS Sender ID Registraion

The Australian Government to Require SMS/MMS Sender ID Registraion Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 26.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. Keine relevanten IPs erfasst (ruhig oder stark gefiltert). Mehr Live-Daten und die komplette Historie im /attacks/ Watchtower-Bereich