Metabase, the open-source business analytics platform, faces a critical zero-day vulnerability that grants attackers remote administrative access to affected instances. The flaw carries maximum severity but remains unassigned a CVE identifier, leaving organisations operating the software in the dark about patching timelines.

The vulnerability exploits Metabase's SQL capabilities, allowing unauthenticated attackers to bypass security controls and gain full administrator privileges. Once an attacker establishes administrative access, they control the analytics platform entirely. This creates a cascading risk: attackers can then pivot toward downstream systems and databases that Metabase connects to, potentially exposing sensitive business data, customer records, and operational intelligence.

Metabase deployments span thousands of organisations globally. The platform connects directly to production databases across finance, retail, healthcare, and technology sectors. A compromised Metabase instance becomes a beachhead for lateral movement into core infrastructure.

The absence of a CVE assignment complicates incident response. Security teams cannot easily track vulnerability status, correlate with vulnerability scanners, or prioritise patches using standard vulnerability management workflows. Organisations must rely on vendor communications and manual tracking until official CVE assignment occurs.

Critical questions remain unanswered. Metabase has not publicly disclosed whether active exploits exist in the wild. No timeline for a patch release has been announced. Defenders lack clarity on whether the vulnerability affects all versions or specific release branches.

Organisations running Metabase should immediately audit network access logs for suspicious administrative login activity and unusual SQL queries. If possible, isolate Metabase instances from production databases until patches arrive. Monitor vendor advisories closely and subscribe to Metabase security notifications.

The blast radius extends beyond direct Metabase operators. Any organisation whose data flows through a compromised Metabase instance faces exposure. Data custodians should contact analytics teams