# Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

_Saturday, August 8, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjv2q8ukeawl9ALLfPnkrRkD2a9umOrSxPHUJdclgLcKj5zM8k19y-NWuTGLrV1yIU4u0F2-QbAsD4zO-NkeEuWPwDqdUYbVFDG69EgOl0v55K0Brjp7lfIb6hExJGyVj9rj5KjeZPtoU97DwoaHAi_umLzQVqpedMMt08eas1akWBhNXUZ2WHOqVXczAf4/s1700-e365/metabase.jpg)

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.

The vulnerability, which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain administrator access to the instance. Metabase said in an advisory that it recently identified that Metabase Cloud was attacked by someone utilizing an unknown zero-day security vulnerability in versions 1.58 and above.

Metabase Cloud instances have already been updated to the latest version. Users running self-hosted versions are advised to apply security patches released by Metabase with immediate effect.

## Sources

- [thehackernews.com](https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html)

---
Canonical: https://techandbusiness.org/newswire/WcfDIxStxc9TFkS3hVnCa4
Retrieved: 2026-08-08T14:45:35.760Z
Publisher: Tech & Business (techandbusiness.org)
