← Back

Wire · regulatory

Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access

Published

9 August 2026

Topic

regulatory

Sectors

Enterprise SoftwareCybersecurity

Source

Read at cybersecuritynews.com

Verified

Fusion42 · 27 August 2026 · Fusion42 review

A critical zero-day SQL injection vulnerability in Metabase, an open-source business intelligence platform, has been exploited in the wild to gain unauthorized full administrator access. While Metabase Cloud customers were automatically patched, self-hosted instances remain vulnerable, leading to confirmed data breaches including customer personal information.

This Wire brief sits within Fusion42's coverage of Enterprise Software and Cybersecurity.

◆ The Wire takeaway

Your Metabase self-hosted deployments are a critical risk until patched. Urgently roll out updates or your data and customer trust will be compromised.

Coverage

1 source · 9 Aug 2026

Related on Wire

Topics

Enterprise SoftwareCybersecuritymetabase0daysql-injectionadmin-accessdata-breachopen-source