CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Products

Metabase Business Intelligence Software Affected by Critical Zero-Day

August 8, 2026

Metabase is a business intelligence and data visualization platform. A critical zero-day vulnerability (CVSS 10.0) allows unauthenticated attackers to inject SQL and gain admin access. All versions from x.58.0 through x.63.2 are affected, with patches available in later releases. Users are urged to update immediately and block the /api/session/reset_password endpoint as a workaround.