← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 8, 2026 · 11:50via Security Affairs

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Brief

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims.

Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own advisory says the vulnerability carries a CVSS score of 10. 0, and it let an unauthenticated attacker inject arbitrary SQL straight into the Metabase application database.

“We recently identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1. 58 and above.” reads the advisory. “We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability.”

Read more on Security Affairs