← العودة للجدول
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
📅 2026-08-08 09:58:31
🔴 Critical 🔥 Yes THN Direct Zero-Day Exploit CVSS 10.0

📋 الوصف الكامل

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

💻 الأنظمة المتأثرة

Intel

⚠️ نوع التهديد

Zero-Day

📡 المصدر

THN Direct

✅ الحلول والتخفيف

Apply vendor security patch

🔗 المصدر الأصلي ←