Metabase CVSS 10.0 Zero-Day Exploited in the Wild
Metabase disclosed that a maximum-severity security flaw (CVSS 10.0, no CVE identifier at time of writing) in its BI and data-visualisation platform was exploited in the wild as a zero-day. The vulnerability allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling full administrator access, configuration changes, credential theft, and data exfiltration.
Overview
| Attribute | Detail |
|---|---|
| Target | Metabase (BI & data-visualisation platform) |
| Type | Unauthenticated SQL Injection |
| CVSS | 10.0 (Critical) |
| CVE | None assigned at time of disclosure |
| Status | Active exploitation in the wild |
| Date | 2026-08-08 |
| Source | The Hacker News |
Impact
- Unauthenticated โ no credentials required to exploit
- Full SQL injection into the Metabase application database
- Administrator access gained to Metabase instances
- Configuration changes, credential theft, and data exfiltration possible
- Metabase Cloud instances patched; self-hosted users must patch immediately
Australian & NZ Significance
Metabase is widely deployed as an open-source BI platform in Australian government, financial services, and mid-market organisations, and in NZ entities under the Privacy Act 2020 and NCSC framework. Australian CISOs should verify self-hosted instances are patched under the Essential Eight schedule and check for anomalous admin account creation or database credential access.
Mitigation
- Apply Metabase security patches immediately (self-hosted instances)
- Audit for unauthorised admin account creation
- Review database credential access logs
- Monitor for anomalous SQL queries or data exfiltration patterns
Related Pages
- Cve 2026 6875 Servicenow Ai โ ServiceNow AI Platform sandbox escape (CVSS 9.5, active exploitation)
- Cve 2026 50522 Sharepoint Server Rce โ Critical SharePoint Server RCE (CVSS 9.8, active exploitation)