Personal care products are among the largest everyday sources of exposure to endocrine-disrupting chemicals, and high schoolers who follow social media influencers or watch beauty tutorials seem to ...
A single unauthenticated HTTP request to Metabase's password-reset endpoint was all it took for an attacker to gain full administrator access to an analytics platform trusted by tens of thousands of ...
A critical SQL injection vulnerability in Metabase, tracked as CVE-2026-72898, could allow unauthenticated remote attackers to compromise vulnerable instances and obtain administrator-level control.
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data. Business intelligence (BI) platform ...
A zero-day SQL-injection vulnerability in Metabase Cloud is under exploitation in the wild, and it could spell trouble for many downstream organizations. Metabase, which provides AI-driven business ...
Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase ...
Metabase has disclosed a critical zero-day SQL injection (SQLi) vulnerability that can allow unauthenticated attackers to gain administrator access to vulnerable instances. The flaw is rated at ...
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. Data analytics solutions provider Metabase has released urgent patches for a ...
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. The company said ...
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants ...
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. Metabase disclosed the ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results