Metabase Zero-Day Forces Patch And Breach Checks
BleepingComputer reported active exploitation of a critical Metabase SQL injection zero-day affecting cloud and self-hosted deployments, with Framework and Tally disclosing customer data exposure.

Attackers used a critical Metabase SQL injection zero-day to break into customer analytics instances and steal data from companies including Framework and Tally, BleepingComputer reported.
Metabase disclosed Thursday that its managed Metabase Cloud service had been attacked through a previously unknown vulnerability affecting versions 1.58 and above.
Self-hosted installations are also vulnerable.
The flaw is an unauthenticated SQL injection vulnerability that can give a remote attacker administrator access to a customer’s Metabase instance.
Metabase has not assigned it a CVE identifier, but its security advisory rates the issue as Critical with a CVSS score of 10.0 and confirms active exploitation.
From an administrator account, an attacker could change application configuration, steal stored credentials for connected databases, read data available through those connections and export information.
That makes a compromised Metabase instance a potential route into the business data stores attached to the analytics tool, rather than only the dashboards displayed in it.
Metabase CEO Sameer Al-Sakran said the company blocked the endpoints used in the attack and rolled out a fix after identifying the intrusion.
Cloud customers have already been upgraded and patched.
Organizations running Metabase themselves must update manually.
What the companies disclosed
Framework confirmed that attackers compromised its Metabase instance and stole customer information.
In a breach notification sent to customers, the laptop maker said the stolen data included full names, email addresses, login IP addresses, billing and shipping address information, phone numbers and company names.
For Framework for Business customers, the exposed data may also include the company name, phone number, VAT, EIN and billing email address.
Metabase notified Framework on August 6 that its instance had been vulnerable to the zero-day and had been accessed by the attacker on August 3.
Tally, the online form builder, also notified users that its Metabase analytics environment was compromised on August 3.
Attackers reached users’ email addresses and password hashes.
Tally said the hashes are one-way and cannot be turned back into passwords, and that forms and submitted answers were stored separately and were not reached.
BleepingComputer asked Tally which password hashing algorithm was used and whether the exposed password hashes were salted, but had not received a response at publication.
LexisNexis separately warned customers that it was affected by a cyberattack at a third-party vendor.
The company did not explicitly link the incident to the Metabase vulnerability, but said its Metabase API was affected along with Diligence and Newsdesk services.
LexisNexis identified unusual activity on servers hosted and managed by a third-party vendor and disconnected from those systems to contain the issue.
Taking the systems offline made the affected applications unavailable while the company investigated.
It remains unclear whether customer data was exposed, and LexisNexis said it was working with a cybersecurity forensic firm.
Patching and detection
Fixed versions are available for affected branches from 0.58 through 0.63.
The minimum safe releases are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5.
Organizations that cannot upgrade immediately should temporarily block access to `/api/session/reset_password` until they can apply the update.
Metabase recommends that self-hosted customers immediately upgrade, revoke all active user sessions, review API keys and administrator accounts for unauthorized changes, rotate credentials for connected databases, and inspect logs and query history for signs of compromise.
One likely attack pattern is a POST request to `/api/session/reset_password` returning a 400 status code, followed by a successful GET request to `/api/user/current`.
Metabase warns that systems showing those log entries have likely been compromised.




















