Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
A zero-day vulnerability in Metabase is being actively exploited in the wild, according to a report from The Hacker News published on August 8, 2026. The flaw allows an attacker to gain admin access to a Metabase instance without requiring authentication. This means that any exposed Metabase deployment could be compromised, granting the attacker full administrative control over the application and its data. The report does not specify which versions of Metabase are affected, nor does it provide technical details of the exploit. However, the fact that it is being exploited in the wild indicates that attackers are actively targeting vulnerable systems. Metabase is a popular open-source business intelligence tool, and this vulnerability could have serious implications for organizations using it. The report does not mention any patches or mitigations, so administrators are left without official guidance from the source. The urgency of the situation is underscored by the active exploitation, which suggests that immediate attention is required to protect affected systems.
Active exploitation of a Metabase zero-day can lead to unauthorized admin access, compromising sensitive data.