[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:metabase-zero-day-exploited-in-wild-allows-admin-access-without-authentication-msk9pms2":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":15,"article_ids":16,"ioc_summary":18,"source_urls":19,"status":21,"expires_at":22,"created_at":23,"updated_at":24,"articles":25},"23e3569b-55c4-4bd9-a8e0-e998a6e5051e","Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication","metabase-zero-day-exploited-in-wild-allows-admin-access-without-authentication-msk9pms2","A CVSS 10.0 zero-day in Metabase is being actively exploited to grant unauthenticated admin access. Self-hosted instances are at immediate risk of data theft, credential exposure, and unauthorized configuration changes. Metabase Cloud has been patched, but self-hosted deployments remain vulnerable.","critical","advisory",[],[13,14],"Metabase","Metabase Cloud","Immediately inventory all Metabase instances (cloud and self-hosted) in your environment. Prioritize patching self-hosted deployments to the latest version. Monitor access logs for unauthenticated admin account creation or privilege escalation attempts.",[17],"aa5b9a52-9c16-468e-bfb4-7ade887ef95b",null,[20],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fmetabase-zero-day-exploited-in-wild.html","archived","2026-08-10T11:05:44.235+00:00","2026-08-08T11:05:51.566472+00:00","2026-08-10T12:06:11.854424+00:00",[26],{"id":17,"title":6,"url":20}]