Published Saturday, August 08, 2026 at 10:15 AM PT

<strong>METABASE ZERO-DAY ACTIVELY EXPLOITED — UNAUTHENTICATED ADMIN ACCESS</strong>

BLUF: Metabase zero-day allowing unauthenticated remote admin access is exploited in the wild. Customer data theft confirmed. Immediate isolation and monitoring required; patch availability pending.

DETAILS

  • SQL injection vulnerability in Metabase permits remote, unauthenticated attackers to achieve full administrative access without credentials
  • Exploitation confirmed active in production environments; customer data exfiltration campaigns underway
  • Vulnerability grants attackers ability to read/export analytics, user accounts, connected database credentials, and underlying data accessible via Metabase queries
  • Reported by multiple independent sources (SecurityAffairs, The Hacker News, BleepingComputer) with consistent exploitation narrative
  • Specific affected version range, CVE identifier, and patch timeline not yet disclosed in available reporting

IMPACT

  • Scope: All Metabase deployments (cloud, on-premises) are potentially vulnerable until patched
  • Access: Attackers gain admin-level control without authentication; no prior foothold required
  • Data at risk: All analytics, credentials, and database access strings stored or queryable within Metabase; any exported datasets since deployment should be considered compromised
  • Active threat: Exploitation is not hypothetical; customer environments have already been targeted

RECOMMENDED ACTIONS

  • NOW: Restrict network access to Metabase to trusted IPs only; log and review all admin account activity for unauthorized additions
  • Urgent: Check Metabase GitHub releases, security advisories, and official channels for patch; have deployment plan ready
  • Interim: Isolate Metabase from production networks if operationally feasible; segregate any connected database credentials
  • After patching: Audit for unauthorized admin accounts created during active exploitation window; rotate database credentials accessible through Metabase
  • Treat all data exported from Metabase as potentially exposed to attackers

SOURCES

  • SecurityAffairs: “Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data”
  • The Hacker News: “Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication”
  • BleepingComputer: “Metabase SQLi zero-day exploited in customer data-theft attacks”

Recent high-severity events at publish time:

Recent high-severity events