Metabase zero-day exploited in the wild

If you run Metabase, patch now.

A maximum-severity zero-day vulnerability in Metabase, the popular open-source business intelligence and data visualisation platform, is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute arbitrary commands on the server.

Metabase is widely deployed across startups and enterprises for internal dashboards and analytics. Many instances sit behind corporate firewalls but are still reachable from internal networks, making lateral movement a real risk once an attacker gains initial access.

The vendor has released patches for all supported versions. If you cannot patch immediately, restrict network access to Metabase instances and monitor for unusual query patterns or process execution.