FR
live
tag

#sql-injection

Metabase Zero-Day CVSS 10.0 Grants Full Admin Access Without Authentication

On August 8, 2026, Metabase disclosed a maximum-severity SQL injection flaw (CVSS 10.0) that was already being exploited in the wild. The vulnerability lets unauthenticated attackers gain administrator privileges and drain every connected database. Self-hosted Metabase admins must patch, revoke sessions, and rotate all secrets immediately.

khunt Weaponizes Oracle's Embedded JVM to Run Post-Exploitation Toolkit from Inside the Database

On August 5, 2026, Huntress researchers documented an attack where the khunt toolkit was compiled and executed inside an Oracle database via SQL injection on an Apache Tomcat endpoint. Attackers abused Oracle's embedded JVM to run OS commands with SYSTEM privileges, steal Windows hashes, and map the network. The message to DBAs is clear: your database is a full Java runtime — treat it like one.

Type at least two characters.

navigate open esc dismiss