Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Cosmos restarted to seize $2.2 million in stolen ATOM, but 169,000 tokens still escaped

    September 24, 2026

    Elephants treat themselves with medicinal plants, witnesses say

    September 24, 2026

    Fat Bear Week opens for Alaska’s heavyweight crown. Can Chunk, the 1,200-pound champ, win again?

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Cosmos restarted to seize $2.2 million in stolen ATOM, but 169,000 tokens still escaped
    • Elephants treat themselves with medicinal plants, witnesses say
    • Fat Bear Week opens for Alaska’s heavyweight crown. Can Chunk, the 1,200-pound champ, win again?
    • Tom Watson’s move to Palantir is the latest sign of how far the rot has spread in UK politics | Clive Lewis
    • Russia slams Kyiv with ballistic missiles as Ukrainians brace for harsh winter
    • Is Burnham right to blame Russia for spreading online disinformation?
    • Holborn and St Pancras: 15 candidates in race to replace Starmer
    • The Global Story – Is a free press at serious risk in Trump’s America?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Metabase SQLi zero-day exploited in customer data-theft attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 8, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally.

    Metabase disclosed the attacks on Thursday, warning that its Metabase Cloud SaaS platform was compromised through a previously unknown vulnerability affecting versions 1.58 and above. The company warns that self-hosted installations are also vulnerable.

    “We recently identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above,” Metabase CEO Sameer Al-Sakran warned in a blog post. 

    image

    Metabase confirmed it blocked the endpoints used for the attack and immediately rolled out a fix for the vulnerability.

    “The vulnerability is an unauthenticated SQL injection flaw in Metabase that can ultimately give a remote attacker administrator access to a customer’s instance.”

    While Metabase has not assigned the vulnerability a CVE identifier, its security advisory rates it as Critical with a CVSS score of 10.0 and confirms that it has been actively exploited.

    “This is a CRITICAL vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance,” reads an associated security advisory.

    “From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. Metabase has confirmed active exploitation of this vulnerability.”

    Metabase is available both as software that organizations can host themselves and through Metabase Cloud, the company’s managed SaaS offering.

    Metabase says its Cloud customers have already been upgraded and patched, while organizations running vulnerable self-hosted installations must update manually.

    The SQLi vulnerability has been fixed in patched versions for all affected branches from 0.58 through 0.63, with the minimum safe releases being 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5.

    Organizations unable to upgrade immediately are advised to temporarily block access to the ‘/api/session/reset_password‘ endpoint until the update can be applied.

    Metabase recommends that self-hosted customers immediately upgrade, revoke all active user sessions, review API keys and administrator accounts for unauthorized changes, rotate credentials for connected databases, and inspect logs and query history for signs of compromise.

    The company says attacks can be identified by a POST request to /api/session/reset_password returning a 400 status code, followed by a successful GET request to /api/user/current.

    Metabase warns that system logs showing these entries have likely been compromised.

    Customers disclose Metabase data theft attacks

    Laptop maker Framework is one of the companies that has confirmed customer information was stolen after attackers compromised its Metabase instance.

    In a breach notification sent to customers and shared with BleepingComputer, Framework said the incident allowed the attackers to steal customer information. The stolen data includes full names, email addresses, login IP addresses, billing and shipping address information, phone number, and company name.

    For Framework for Business customers, the data may also include the company name, phone number, VAT, EIN, and billing email address.

    Framework said Metabase notified the company on August 6 that its instance had been vulnerable to the zero-day and accessed by the attacker on August 3.

    Tally, the popular online form builder, has also notified users that its Metabase analytics environment was compromised on August 3.

    “Through that they reached your email address, and your password as a cryptographic hash. A hash is one-way, so it can’t be turned back into your password. They didn’t reach your forms, or the answers people submitted to them. Those are stored separately.”

    BleepingComputer asked Tally which password hashing algorithm was used and whether the exposed password hashes were salted, but had not received a response at the time of publication.

    In an email shared with BleepingComputer, LexisNexis is warning customers that it was impacted by a cyberattack at one of its third-party vendors.

    While the company did not specifically state it was linked to the Metabase API, it did say its Metabase API was impacted by the attack.

    “We are writing to provide an update on the service disruption affecting Diligence, Metabase API and Newsdesk,” reads the LexisNexis email.

    “Earlier this week, we identified unusual activity on servers that are hosted and managed by a third-party vendor. To protect our customers and contain the issue at its source, we made the immediate decision to disconnect from those third-party systems.”

    LexisNexis said taking the systems offline caused the affected applications to become unavailable, but it was necessary while the company investigated.

    It is unclear whether customer data was exposed during the attack, but the company says it is working with a cybersecurity forensic firm to investigate the incident.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attacks customer datatheft Exploited Metabase SQLi ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

    OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

    58 hardware vulnerabilities: A guide to the threats

    Critical WordPress Vulnerability Exploited Immediately After Disclosure

    Hackers start exploiting critical WordPress flaw for code execution

    Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Cosmos restarted to seize $2.2 million in stolen ATOM, but 169,000 tokens still escaped

    September 24, 2026

    Elephants treat themselves with medicinal plants, witnesses say

    September 24, 2026

    Fat Bear Week opens for Alaska’s heavyweight crown. Can Chunk, the 1,200-pound champ, win again?

    September 24, 2026

    Tom Watson’s move to Palantir is the latest sign of how far the rot has spread in UK politics | Clive Lewis

    September 24, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Cosmos restarted to seize $2.2 million in stolen ATOM, but 169,000 tokens still escaped

    September 24, 2026

    Elephants treat themselves with medicinal plants, witnesses say

    September 24, 2026

    Fat Bear Week opens for Alaska’s heavyweight crown. Can Chunk, the 1,200-pound champ, win again?

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.