TGViewer
Netlas.io Netlas.io @netlas · 2.31K subscribers
Post #609 513
0-day SQL Injection in Metabase, no CVE assigned yet, 10.0 rating ‍🔥🔥🔥

Recently disclosed vulnerability in Metabase allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. This vulnerability is already being actively exploited in the wild!

Search at Netlas.io:
👉 Link: https://nt.ls/q4U1I
👉 Dork: http.favicon.hash_sha256:61c0353e2bde23f74f7febc277df979fbc1017186de060fd9bd8d07b65bcac13 OR http.headers.set_cookie:"metabase.DEVICE" OR http.title:"Metabase"

Vendor's advisory:
https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
  • 🔥 4
  • ❤ 2
  • 👍 2
More from @netlas
  1. Sep 22, 2026CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating 🔥 A rece…
  2. Sep 21, 2026CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating 🔥 S…
  3. Sep 18, 202611 new vulnerabilities in WordPress, no CVE assigned yet ❗️ WordPress 7.1.1 security relea…
  4. Sep 17, 2026CVE-2026-20329 and others: Multiple vulnerabilities in Cisco ASA, up to 9.9 Rating 🔥 Cisc…
  5. Sep 16, 2026CVE-2026-61642: Request smuggling is possible in Squid proxy, 7.7 Rating 🔥 A recently dis…
  6. Sep 15, 2026CVE-2026-78006 & CVE-2026-78159: Two unauthenticated vulnerability chains leading to RCE i…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →