Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.

The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Attack Update: Top 5 Attack-IPs auf doode.info – 12.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 74.7.242.19 — 1759 requests (recent log) 89.167.35.212 — 936 requests (recent log) 34.53.194.57 — 624 requests (recent

Why developers are ditching GitHub for Codeberg and self-hosting alternatives

Why developers are ditching GitHub for Codeberg and self-hosting alternatives Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 30.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 616 requests (recent log) 136.66.143.67 — 282 requests (recent log) 34.26.62.24 — 280 requests (recent