Metabase Business Intelligence Software Affected by Critical Zero-Day
August 8, 2026
Metabase is a business intelligence and data visualization platform. A critical zero-day vulnerability (CVSS 10.0) allows unauthenticated attackers to inject SQL and gain admin access. All versions from x.58.0 through x.63.2 are affected, with patches available in later releases. Users are urged to update immediately and block the /api/session/reset_password endpoint as a workaround.