THREATOPS
THREAT OPSThreat News › Critical Metabase Zero-Day Exploited

Critical Metabase Zero-Day Exploited

medsocradar_blogPublished 2026-08-10

<h1>Critical Metabase Zero-Day Exploited</h1> <p>Metabase has disclosed a critical zero-day SQL injection (SQLi) vulnerability that can allow unauthenticated attackers to gain administrator access to vulnerable instances. The flaw is rated at <strong>maximum severity</strong>, and the vendor has <strong>confirmed active exploitation</strong>.</p> <p>The risk is highest for <strong>self-hosted depl

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://socradar.io/blog/critical-metabase-zero-day/