Metabase disclosed a critical unauthenticated SQL injection zero-day affecting 1.58+ that was actively exploited against Metabase Cloud tenants and vulnerable self-hosted deployments. The company said the flaw could give remote attackers administrator access and enable theft of stored database credentials and accessible data; it has since blocked the attack paths and released fixes. Metabase rated the issue CVSS 10.0 and urged self-hosted customers to upgrade, revoke sessions, rotate credentials, and review logs for signs of compromise.
The downstream impact has already hit multiple organizations. Framework told customers that attackers breached its Metabase-hosted cloud instance through the upstream provider and stole personal data affecting all customers, including names, email addresses, phone numbers, and physical addresses, but not payment information. Tally separately said an attacker accessed its Metabase analytics service and obtained user email addresses and password hashes, while stating that forms and submitted responses were stored separately and were not accessed. LexisNexis also reported disruption and unusual activity involving systems connected to its Metabase API through a third-party vendor.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
A CVE record for a separate Metabase SQL injection vulnerability was published as CVE-2026-72899, listing affected and fixed versions across release branches 58 through 63. The associated SSVC data coordinated by CISA stated there was no known exploitation, while rating the flaw as automatable with total technical impact.
A CVE record for the Metabase password-reset SQL injection vulnerability was published as CVE-2026-72898, classifying it as critical and documenting that unauthenticated attackers could gain administrator access. The record also listed affected and fixed version ranges across Metabase release branches.
n8n disclosed that the Metabase incident exposed 136 customer records containing names and email addresses for self-hosted and n8n Cloud users. The company said five records included bcrypt-hashed cloud-account passwords and separately contacted 25 users whose passwords had been stored in plaintext due to a previously fixed vulnerability.
LexisNexis told customers that a cyberattack affecting a third-party vendor disrupted Diligence, Metabase API, and Newsdesk services. The company said it detected unusual activity on vendor-managed servers and disconnected from those systems while investigating.
Metabase publicly disclosed a critical unauthenticated SQL injection zero-day affecting Metabase Cloud and self-hosted versions 1.58 and above, saying it had been actively exploited in the wild. The company said it blocked the attack endpoints, patched its cloud service, and released fixed versions for self-hosted customers.
Tally disclosed to users that the Metabase compromise exposed user email addresses and password hashes. The company said forms and submitted responses were not accessed because they are stored separately.
Framework notified customers that hackers stole personal information after compromising upstream provider Metabase. The company said all customers were affected and that exposed data included names, email addresses, phone numbers, and physical addresses, but not payment information.
Framework said exposed records included login IP addresses in addition to names, email addresses, phone numbers, and billing and shipping information, and that business-account data may also have been affected. The company also said it rotated database-linked credentials, found no evidence of compromise outside the Metabase environment, and is reviewing how much internal data it shares with external analytics tools.
Framework said Metabase notified the company on August 6 that its instance had been vulnerable to the zero-day and had been accessed by the attacker. Framework then investigated and determined that customer personal data had been stolen.
Framework said Metabase later informed it that attackers accessed Framework's cloud instance on August 3. Tally also said an attacker gained unauthorized access to its Metabase analytics environment on August 3, exposing user email addresses and password hashes.
The reference states that Framework had previously suffered a separate breach in January 2024 through third-party accounting firm Keating Consulting. That earlier incident exposed customer names and email addresses.
Kilo Code notified users that attackers accessed customer data through the Metabase incident, including names, email addresses, and customers' Slack access tokens. The company said it immediately invalidated the exposed Slack access tokens.
Metabase shared indicators of compromise for the exploited zero-day, including a suspicious POST to /api/session/reset_password followed by a successful GET to /api/user/current. It also advised customers to revoke active sessions and review API keys, admin accounts, connected database credentials, and logs after patching.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
27 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcedarkreading.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecommunity.frame.work
Open sourcemetabase.com
Open sourcereddit.com
Open sourcecert.gov.py
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.