NG Solution Team
Cybersecurity

Metabase zero-day exploited to access customer data

Framework, the San Francisco laptop maker, has confirmed a data breach after attackers exploited a zero-day vulnerability in the Metabase business intelligence service and accessed customer personal data. According to a notification sent to affected customers, the attackers obtained names, email addresses, phone numbers, physical addresses and login IP addresses; Framework said payment information and order records were not accessed.

Framework said it was notified of the breach by Metabase, which confirmed attackers gained access to Framework’s cloud instance. Framework has rotated credentials for the databases it connected to its Metabase instance and said it has not yet found evidence of a wider compromise. The company warned affected customers to be vigilant for phishing attempts that impersonate Framework.

Other companies affected

Belgian form-builder Tally (Tally Forms) and Kilo Code, an AI coding platform now owned by Texas-based Anaconda, also told users they were impacted through Metabase. Tally said the exposed data included email addresses and password hashes. Kilo Code reported that attackers accessed names, email addresses and customers’ Slack access tokens; those tokens were immediately invalidated.

Metabase vulnerability and recommended mitigations

On August 6, 2026, the company behind Metabase disclosed that Metabase Cloud was attacked via a zero-day SQL injection vulnerability that currently has no CVE number. In its advisory the company said: “This is a CRITICAL vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data,” the company stated in the advisory.

The vulnerability affects Metabase versions 58 and above. Metabase has released fixes for each affected version and advised customers who self-host to upgrade to a fixed release; revoke active sessions; review API keys and admin accounts; rotate credentials; review data warehouse logs for signs of unauthorized access; and inspect Metabase activity and query history for unexpected or unauthorized activity. The company said the attack pattern looks like a POST to /api/session/reset_password returning a 400 status code followed by a GET to /api/user/current returning a 200 status code; finding that sequence in application or ingress logs likely indicates compromise. Customers unable to upgrade immediately were advised to temporarily block the /api/session/reset_password endpoint.

Related posts

How vulnerable is Latvia’s strategic infrastructure to cyberattacks?

Jessica Williams

How did a 73-year-old woman lose $42,000 to a Microsoft phishing scam?

Jessica Williams

Is there a hidden admin backdoor in Tenda routers allowing unauthorized remote access?

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy