Live Cybersecurity News Ticker | Codekeeper

Metabase Zero-Day Flaw Lets Attackers Seize Admin Access Without Logging In

Written by Content Team | Aug 10, 2026, 12:22:21 PM

A critical zero-day in Metabase, the popular open-source business intelligence platform, is being actively exploited in the wild. Tracked as GHSA-vwf4-m7j8-wcjf with a perfect CVSS score of 10.0, the flaw lets unauthenticated attackers inject SQL through the password reset endpoint and promote themselves to full administrator.

Metabase discovered the breach on August 3 after its own cloud platform was compromised. Cloud customers were patched automatically, but self-hosted users must upgrade manually. At least two companies — Framework and Tally — have already reported customer data theft. Admins should patch immediately and treat any instance showing the exploit's log signature as compromised.

Source: Cybersecurity News