Wire · regulatory
Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 27 August 2026 · Fusion42 review
A critical zero-day SQL injection vulnerability in Metabase, an open-source business intelligence platform, has been exploited in the wild to gain unauthorized full administrator access. While Metabase Cloud customers were automatically patched, self-hosted instances remain vulnerable, leading to confirmed data breaches including customer personal information.
This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity.
◆ ◆ The Wire takeaway
Your Metabase self-hosted deployments are a critical risk until patched. Urgently roll out updates or your data and customer trust will be compromised.
◆ Coverage
1 source · 9 Aug 2026
◆ Related on Wire
◆ Topics