ShellCodeX Intelligence Brief
CRITICAL
Vulnerabilities
Metabase zero-day lets unauthenticated attackers gain admin via SQL injection
Source headline: Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Threat level
Critical
Signal strength
90/100
Source confidence
1 source
Published
2 hours ago
Intelligence Summary
Metabase disclosed a maximum-severity zero-day flaw affecting its BI and data visualization platform. The issue is being exploited in the wild, with no CVE assigned yet. It allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase backend database. Successful exploitation can lead to administrative access and compromise of the application. Organizations running Metabase should review exposure, apply available mitigations, and monitor for suspicious database and admin activity.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.
Topics
Original reporting
The Hacker News
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Open original source