< Back to all clusters
[TECHNOLOGY] · United States · 7 sources

started · updated

Metabase patches critical zero‑day SQL injection after data breach

Metabase disclosed that a zero‑day SQL injection vulnerability affecting versions 1.58 and later was exploited to steal sensitive customer information, including names, email addresses, phone numbers, billing and shipping details. The attack was first detected on August 3, 2026 and publicly reported on August 6, 2026. Both self‑hosted Metabase installations and the Metabase Cloud service were impacted, allowing unauthenticated attackers to execute arbitrary database queries and gain administrative access.

Customers Framework and Tally confirmed that their data had been accessed. Metabase has since patched the flaw, advised all users to apply the update immediately, rotate database credentials, review admin accounts, and revoke any compromised API keys. The company notified law enforcement and engaged a third‑party forensics firm. No form responses were accessed, and password data was exposed only as hashes.

Entities

Framework · Metabase · Tally