Observed Signal · Aug 8, 2026 · Vulnerability Disclosure · Source: DEV Community · Impact: 3/5 · Sentiment: Negative

Metabase Zero-Day (CVSS 10.0) Enables Admin Takeover

Executive Signal Summary

Metabase disclosed an in-the-wild zero-day: an unauthenticated SQL injection in its BI platform (rated CVSS 10.0) that allows remote attackers to write to the application database and escalate themselves to administrator. Metabase Cloud has been patched by the vendor; self-hosted deployments across six release branches must update to specific fixed versions (listed per branch) or apply the vendor-recommended temporary mitigation of blocking the /api/session/reset_password endpoint. The vulnerability exposes stored credentials for every connected database, so compromise can lead to data exfiltration across warehouses. Framework is a confirmed downstream victim; Metabase advises post-patch cleanup including revoking sessions, auditing accounts and API keys, and rotating credentials for all connected databases.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A confirmed, in-the-wild pre-authentication CVSS 10.0 vulnerability in a widely-used BI/analytics platform puts stored database credentials and connected data warehouses at risk; requires immediate patching for self-hosted instances and credential rotation, but is not a platform-wide industry policy change.

SIGNAL RADAR

Track Real-Time Security Vulnerability Signals & Market Shifts

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • An unauthenticated SQL injection in Metabase was exploited in the wild and rated CVSS 10.0.
  • No CVE identifier was assigned at the time of disclosure.
  • Six Metabase release branches (>= x.58.0 through < x.63.3 ranges) received branch-specific fixes; exact fixed versions are required (e.g., x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, x.63.5).
  • Metabase Cloud instances were updated by the vendor; self-hosted users must patch or block /api/session/reset_password as a temporary mitigation.
  • PC maker Framework confirmed data access during the incident (customer names, addresses, phone numbers, emails, and login IPs).
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Aug 8, 2026
Original Coverage Title: “Metabase Zero-Day Hits CVSS 10.0: Unauthenticated SQL Injection Gives Full Admin”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Privacy / Data breachAug 7, 2026

Framework notifies all customers of data breach

Framework, a maker of modular repairable computers, notified all customers that hackers accessed personal information — including names, email addresses, phone numbers and physical addresses — after an upstream cyberattack at business-intelligence provider Metabase. Framework said payment information was not included. Metabase disclosed it was hacked via an unknown security flaw (a zero-day) that allowed attackers access to customers' databases stored on its cloud servers. Framework's spokesperson Eric Schumacher confirmed the breach affected "all customers" but did not provide a precise number.

Read assessment
InfrastructureJul 14, 2026

Cisco patches CVSS 10.0 Secure Workload authentication bypass

Cisco released emergency patches addressing a maximum-severity authentication-bypass vulnerability in its Secure Workload platform (tracked as CVE-2026-20223) that earned a CVSS 10.0 score. The flaw allows unauthenticated remote attackers to gain Site Admin privileges by sending specially crafted requests to Secure Workload's REST API, bypassing authentication. The vulnerability affects both SaaS-hosted and on-premises deployments, can enable cross-tenant access to sensitive telemetry and configuration, and has no known workaround — Cisco recommends applying the fixes immediately. Security publishers noted this is one of several 'perfect 10' bugs disclosed for Cisco in 2026 and emphasized the broad impact on enterprises that use Secure Workload as part of zero-trust and micro-segmentation architectures.

Read assessment
SecurityFeb 11, 2026

Microsoft Patches Critical Zero-Day Bugs Targeting Windows Users

Microsoft released security updates fixing multiple zero-day vulnerabilities in Windows and Office that the company says are being actively exploited by hackers. At least two flaws enable one-click attacks — tricking a user into clicking a malicious link — and another allows compromise via a malicious Office file. Microsoft identified one flaw as CVE-2026-21510 in the Windows shell, affecting all supported Windows versions and able to bypass SmartScreen; another is CVE-2026-21513 in the MSHTML engine used for backward compatibility. Microsoft acknowledged input from Google’s Threat Intelligence Group and said exploit details have been published. Independent reporting (Brian Krebs) notes additional zero-days were patched. Security experts warned the bugs permit remote malware installation and high‑privilege silent execution, increasing risk of system compromise and ransomware.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.