ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

Metabase zero-day lets unauthenticated attackers gain admin via SQL injection

Source headline: Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Threat level Critical
Signal strength 90/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

Metabase disclosed a maximum-severity zero-day flaw affecting its BI and data visualization platform. The issue is being exploited in the wild, with no CVE assigned yet. It allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase backend database. Successful exploitation can lead to administrative access and compromise of the application. Organizations running Metabase should review exposure, apply available mitigations, and monitor for suspicious database and admin activity.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#zero-day #unauthenticated #sql-injection #metabase #exploitation-in-wild
Original reporting The Hacker News Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Open original source