Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
What happened
A maximum-severity zero-day SQL injection vulnerability in Metabase allows unauthenticated remote attackers to gain administrative access. The flaw is currently being exploited in the wild to facilitate customer data theft.
Why it ranks #1
Confirmed active exploitation of a CVSS 10.0 zero-day providing full admin access represents the highest possible urgency tier.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Apply available vendor patches immediately and audit database logs for unauthorized SQL injection attempts.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed