Metabase zero-day lets attackers take over your business data

Published August 10, 2026

A serious flaw in Metabase lets attackers bypass your login and take over your company's data. They can then see, change, or delete anything stored in the platform.

Severity
Not scoredNo CVSS score recorded
Fix
Not confirmed
Affects
Metabase
Exploited
Not confirmedNo confirmation recorded

How it works

An attacker sends a specially crafted request to Metabase's admin panel that tricks it into giving them full access without a password.

What to do

Check whether the installed Metabase version is older than the fixed version in the vendor advisory or current release.

Update Metabase through its normal update channel, then confirm the installed version matches the newest vendor release.

Technical details

The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.