Digest
CRITICAL

Metabase Zero-Day SQLi Actively Exploited for Data Theft

A critical, unpatched SQL injection vulnerability in Metabase’s business intelligence software (CVSS 10.0) is being actively exploited in the wild. Attackers are using this zero-day to inject arbitrary SQL, gain administrative access without authentication, and steal customer data. This vulnerability has already impacted companies like Framework and Tally, leading to data theft incidents.

← Back to the feed

Trending Tags