Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

A maximum-severity zero-day vulnerability in Metabase, lacking a CVE, enables remote attackers to gain administrator access to the business-analytics platform and potentially compromise its downstream users.

A maximum-severity zero-day vulnerability in the Metabase business-analytics platform allows remote attackers to gain administrator access, with no CVE assigned yet. The flaw could have a wide blast radius, affecting the platform itself and its downstream users. Attackers can exploit the SQL vulnerability to compromise admin accounts, potentially accessing sensitive data and pivoting to connected systems. No patch or mitigation details have been released as of now.