Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

A Critical Zero-Day Vulnerability in Metabase Exposes Admin Access Without Authentication, Leaving Many Organizations Vulnerable

A newly discovered zero-day vulnerability in the popular data analytics platform Metabase has been exploited in the wild, allowing attackers to gain administrative access without requiring any authentication credentials. This critical flaw affects numerous organizations worldwide that rely on Metabase for data visualization and insights.

The vulnerability, which was first reported by security researchers, allows an attacker to bypass Metabase’s authentication mechanisms and assume a privileged role within the system. This essentially grants them unlimited access to sensitive data, settings, and configurations, making it an attractive target for malicious actors. The impact is not limited to just data theft; with admin access, attackers can also modify settings, inject malware, or even take control of entire systems.

The vulnerability is rooted in Metabase’s handling of cross-domain privilege escalation, a complex technical concept that essentially allows an attacker to elevate their privileges across different domains within the system. This is achieved through a clever manipulation of permissions and roles, which are often not properly configured or monitored. In simple terms, it’s like finding a backdoor into a high-security facility – once inside, the attacker can move freely and undetected.

The affected versions of Metabase include all those up to 1.35.1, which means many organizations may be exposed to this vulnerability without even realizing it. The fact that this zero-day exploit has been seen in the wild raises serious concerns about the potential for widespread attacks. With administrative access granted, attackers can move laterally within an organization’s network, exploiting other vulnerabilities and causing significant damage.

Metabase is a widely used platform, especially among smaller to medium-sized organizations, which may not have the same level of security expertise as larger enterprises. This makes it even more critical that users take immediate action to patch their systems and harden their Metabase configurations. The exploit’s ability to bypass authentication mechanisms also highlights the importance of regular security audits and vulnerability assessments to detect and address potential weaknesses.

In light of this discovery, we urge all Metabase administrators to update their software to the latest version (1.35.2) as soon as possible and review their system settings for any signs of unauthorized access or activity. This is a timely reminder that even seemingly secure systems can be vulnerable to exploitation if not properly maintained and configured.


Source: The Hacker News — 2026-08-08