Skip to content
The Nexus
SECURITYAug 8 · 06:58 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase warned that a maximum-severity security flaw in its business intelligence and data visualization software has been exploited as a zero-day. The vulnerability, which has a CVSS score of 10.0, allows an unauthenticated remote attacker to inject arbitrary SQL into the application database. This capability could enable attackers to gain admin access without authentication.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting