Metabase SQLi zero-day exploited in customer data-theft attacks

Critical Metabase Vulnerability Exposes Customer Data in Widespread Attacks

A devastating zero-day vulnerability in Metabase, a popular business intelligence and data analytics platform, has been exploited by attackers to steal sensitive customer information from multiple companies. The attacks, which have been confirmed to impact Framework and Tally, demonstrate the severity of the vulnerability and highlight the importance of timely patching and monitoring for organizations using the platform.

Metabase, in a security advisory published on Thursday, revealed that its cloud-based SaaS platform was compromised through an unknown (0-day) vulnerability affecting versions 1.58 and above. The company warned that self-hosted installations are also vulnerable to the attack, which can grant remote attackers administrator access to customer instances. This allows attackers to inject arbitrary SQL into the Metabase application database, compromising sensitive data.

The vulnerability is categorized as Critical with a CVSS score of 10.0, indicating its severity and potential impact. The security advisory notes that an unauthenticated remote attacker can exploit this flaw to gain full control over the instance, allowing them to modify configuration settings, steal stored credentials for connected databases, read any accessible data, and export sensitive information.

One of the companies affected by the attack is Framework, a laptop maker that has confirmed customer information was stolen after attackers compromised its Metabase instance. The breach notification sent to customers revealed that the attackers had access to full names, email addresses, login IP addresses, billing and shipping address information, phone number, and company name.

Tally, an online form builder, also notified users that its Metabase analytics environment was compromised on August 3. Although Tally assured users that their forms and submitted answers were not accessed, the attack still poses a significant risk to customer data security.

Metabase has taken steps to address the vulnerability by blocking the exploited endpoints and rolling out patches for affected versions. The company recommends that self-hosted customers immediately upgrade to patched versions, revoke active user sessions, review API keys and administrator accounts for unauthorized changes, rotate credentials for connected databases, and inspect logs and query history for signs of compromise.

For organizations using Metabase, it is essential to take immediate action to protect customer data. If you are unable to upgrade immediately, consider temporarily blocking access to the ‘/api/session/reset_password’ endpoint until the update can be applied. Regularly monitoring system logs and network activity will also help identify potential signs of compromise. By staying vigilant and taking proactive measures, organizations can minimize the risk of falling victim to such attacks.

Ultimately, this incident highlights the importance of maintaining up-to-date software and keeping a close eye on security advisories. With Metabase’s prompt response and patching efforts, affected customers can now rest assured that their data is safer than before.


Source: Bleeping Computer — 2026-08-07