BleepingComputerSaturday · August 8, 2026FREE

Metabase SQLi zero-day exploited in customer data-theft attacks

metabasesql-injectionzero-daysecurity

According to BleepingComputer, a Metabase SQL injection zero-day vulnerability was exploited in customer data-theft attacks. The attacks were disclosed by Framework and Tally, two companies that appear to have been affected. The source does not specify the exact version of Metabase affected, the nature of the data stolen, or the number of customers impacted. It also does not provide technical details about the vulnerability or the attack methodology. The disclosure highlights that the vulnerability was actively exploited in the wild, underscoring the risk to organizations using Metabase. The source does not include any remediation steps or recommendations, nor does it mention whether patches were available at the time of disclosure. The incident serves as a reminder of the ongoing threat posed by zero-day vulnerabilities in widely used open-source tools.

// why it matters

Metabase users face active exploitation of a zero-day SQLi vulnerability, risking customer data theft.

Sources

Primary · BleepingComputerMirror · DEV Community
▸ Read original at bleepingcomputer.com

Like this? Get the next digest.

Metabase SQLi zero-day exploited in customer data-theft attacks — aigest.dev