Published Monday, August 10, 2026 at 04:20 AM PT

<strong>Metabase Zero-Day Exploited in Wild — Unauthenticated Admin Access</strong>

BLUF: Metabase has patched a zero-day vulnerability actively exploited in the wild that grants unauthenticated, remote attackers full administrative access to affected instances. Immediately check for exploitation and apply the patch.

DETAILS:

  • The vulnerability allows unauthenticated, remote attackers to gain full administrative access to Metabase instances without any credentials (confirmed by SecurityWeek, SecurityAffairs, The Hacker News).
  • Exploitation is confirmed active in the wild — this is not theoretical; multiple sources report ongoing attacks targeting live Metabase deployments.
  • Sensitive data exposure is confirmed as a result of successful exploitation.
  • Metabase has released a patch; specific affected versions, CVE number, and patch version numbers are not yet disclosed in available reporting.
  • Technical vulnerability details remain limited in initial public disclosures.

IMPACT:

  • Any Metabase instance accessible over a network (internet-facing or otherwise) is at immediate risk.
  • Compromise grants complete administrative privileges: data exfiltration, user/credential management, report modification, system reconfiguration.
  • Affected teams: BI analysts, data engineers, compliance/audit functions, and anyone relying on Metabase for dashboarding and query access.
  • Scope is broad — no version pins, no access restrictions, and no authentication requirement to trigger the flaw.

RECOMMENDED ACTIONS:

  1. Immediately inventory all Metabase deployments — internal, cloud-hosted, and any instance not behind a restrictive firewall.
  2. Locate and apply the patch — check Metabase’s official release notes and security advisories for the patched version; deploy without delay.
  3. Audit access logs — review authentication and admin action logs for the period before the patch became available; look for unauthenticated admin sessions.
  4. Quarantine unpatched instances — if an instance cannot be patched immediately, isolate it from network access.
  5. Assume compromise on exposed instances — any Metabase accessible to the internet before patching should be treated as potentially compromised; audit for data access patterns, new admin accounts, and lateral movement.

SOURCES:

  • SecurityWeek: “Metabase Patches Vulnerability Exploited as Zero-Day”
  • SecurityAffairs: “Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data”
  • The Hacker News: “Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication”

Recent high-severity events at publish time:

Recent high-severity events