Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a critical zero-day vulnerability (CVSS 10.0) in its business intelligence software is being actively exploited, allowing unauthenticated attackers to inject arbitrary SQL and gain admin access.

Metabase warned a maximum-severity zero-day (CVSS 10.0) in its business intelligence software is being exploited in the wild. The flaw allows unauthenticated remote attackers to inject arbitrary SQL into the application database, granting admin access without credentials. No CVE identifier has been assigned.