
Metabase Zero-Day Attack Lets Hackers Gain Admin Access and Steal Database Credentials
A maximum-severity, unauthenticated SQL injection zero-day in the popular open-source analytics platform Metabase has been actively exploited in the wild, letting attackers seize administrator privileges and steal credentials for every database connected to compromised instances. Metabase disclosed that its Cloud infrastructure was targeted starting around August 3, 2026, when attackers weaponized a previously unknown flaw […]
The post Metabase Zero-Day Attack Lets Hackers Gain Admin Access and Steal Database Credentials appeared first on Cyber Security News.