AI-Generated · qwen3.6:latest

Zero-day Metabase SQL injection flaw exploited in wild to breach Framework, Tally, and others

Metabase disclosed a zero-day SQL injection flaw rated CVSS 10.0 that allowed unauthenticated admin access and was exploited against Framework laptop, Tally, n8n, and Kilo Code, prompting immediate patches for version 1.58+ and data breach notifications across affected organizations.

Zero-day Metabase SQL injection flaw exploited in wild to breach Framework, Tally, and others
Data Security Breach — illustrating the broader category of cyber vulnerabilities like the zero-day SQL injection flaw that affected Metabase and its customers (file photo)
Photo: Visual Content, CC BY 2.0

Metabase disclosed a critical vulnerability in its business intelligence platform that allowed attackers to seize administrator privileges without any authentication, with the company moving quickly to address the flaw across its cloud infrastructure and customer deployments. The vendor confirmed that it released patches for versions 1.58 and newer immediately after the disclosure closed, following a gap during which unauthenticated users had exploited the zero-day to access exported database contents and bypass security controls entirely.

The vulnerability, which functions as a SQL injection flaw that permits arbitrary database commands to be executed without valid credentials, carries a maximum CVSS severity rating of 10.0, with independent analysis confirming the exploit is actively being weaponized in real-world attacks during the window between discovery and mitigation. Broader assessment of the campaign revealed that attackers were not confined to Metabase’s internal systems; instead, they identified and hijacked Metabase instances operated by external organizations, moving laterally within those compromised environments to access the sensitive data stores connected to them.

This cross-tenant exploitation resulted in confirmed breaches across multiple distinct technology sectors, with reports indicating Metabase deployments belonging to Framework laptop, Tally, n8n, and Kilo Code were successfully targeted through active exploitation in the wild. The impact on these organizations stemmed from their reliance on Metabase for analytics and reporting rather than direct network penetration: attackers only needed to find a vulnerable business intelligence instance that aggregated internal records, turning a single vulnerability in a visualization layer into a direct conduit for stealing customer and operational data across disparate companies.

Framework, the modular computer maker, became one of the most visible examples of the breach’s scope, prompting the firm to alert its entire user base after discovering attackers had accessed sensitive records through a compromised Metabase database linked to its operations. The company’s public notice confirmed that customers were notified of data exposure including names, email addresses, phone numbers, and physical mailing addresses from an upstream Metabase zero-day breach, while payment information was excluded from the stolen dataset. This distinction defined the immediate risk profile for affected users: while personal contact details and identity information had been exfiltrated, the absence of financial credentials removed the threat of unauthorized charges, though the exposure still necessitated alerts for potential identity fraud.

The incident underscores how centralizing analytics data within shared platforms can amplify the fallout from a single software flaw; as vendors issue rapid updates and compromised firms assess their own exposure across different instances, the breach serves as a reminder that vulnerabilities in third-party visualization tools can effectively function as administrative backdoors into core business databases. Organizations relying on such platforms must now verify that all managed deployments have been updated beyond version 1.58 and audit their configurations to ensure no residual access remains open to adversaries who may have gained footholds before the patch window closed.

The diversity of entities affected—from hardware manufacturing and software infrastructure to developer tooling—demonstrates that no specific industry was immune to the consequences of a BI system being weaponized, reinforcing the need for rigorous version control and continuous monitoring across all business intelligence installations. As the community grapples with the aftermath, the event highlights the delicate balance between leveraging analytics platforms for operational insight and the inherent risks of trusting them with sensitive data reservoirs without assuming that the platform itself guarantees isolation from the vulnerabilities attackers are actively scanning for in the wild.

Sources