Security News Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication TheHackerNews Daniel Bender 08 Aug 2026 Share Metabase says a CVSS 10.0 zero-day SQL injection was exploited in the wild; the flaw can grant admin access and expose connected database data.