
๐ก๏ธ **Metabase Zero-Day Exploited in Wild โ Unauthenticated Admin Access**
Published Monday, August 10, 2026 at 04:20 AM PT BLUF: Metabase has patched a zero-day vulnerability actively exploited in the wild that grants unauthenticated, remote attackers full administrative access to affected instances. Immediately check for exploitation and apply the patch. DETAILS: The vulnerability allows unauthenticated, remote attackers to gain full administrative access to Metabase instances without any credentials (confirmed by SecurityWeek, SecurityAffairs, The Hacker News). Exploitation is confirmed active in the wild โ this is not theoretical; multiple sources report ongoing attacks targeting live Metabase deployments. Sensitive data exposure is confirmed as a result of successful exploitation. Metabase has released a patch; specific affected versions, CVE number, and patch version numbers are not yet disclosed in available reporting. Technical vulnerability details remain limited in initial public disclosures. IMPACT: ...