bleeping-computer · Crawled Aug 7, 2026
Metabase SQLi zero-day exploited in customer data-theft attacks
2 IoCs
Read original article ↗
AI Summary
A critical unauthenticated SQL injection vulnerability in Metabase versions 1.58 and above was exploited in zero-day attacks to compromise customer instances, leading to data theft at organizations including Framework, Tally, and a third-party vendor used by LexisNexis. The vulnerability allowed attackers to gain administrator access to Metabase instances, enabling them to steal stored credentials, read accessible data, and export customer information. Metabase confirmed active exploitation and issued patches across multiple affected branches, urging self-hosted users to update immediately and rotate credentials.
AI-extracted · verify before operational use