Metabase SQLi zero-day exploited in customer data-theft attacks
Attackers exploited a critical SQL injection zero-day in Metabase, a widely used business intelligence tool, to steal data from customer instances before a patch was available. The vulnerability is confirmed to have been used against at least two organizations, Framework and Tally.
Why this matters: Metabase sits inside a lot of companies precisely because it connects directly to databases. That is what makes this bad. A SQL injection flaw in a tool built to query your data is about as direct a path to sensitive records as attackers can find. If your company runs Metabase, this is not a theoretical risk. Customer data was already taken before most people knew the hole existed. Zero-days like this put defenders in an impossible position, but the response speed and transparency of vendors is where accountability actually lives.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.