ATLAS · LIVE
ATLAS INDEX
Δ 24H
ACTIVE SOURCES20
HOTSPOTS20
TIME23:56:19 UTC
← All briefs
CRITICALCyber IntelligenceSaturday, August 8, 2026

Metabase zero-day exploited to breach Framework, Tally customer databases

A critical SQL injection flaw in Metabase analytics software was used in active attacks before disclosure, compromising customer data at multiple firms.

A previously unknown SQL injection vulnerability in Metabase — open-source business intelligence software used by thousands of organizations — was exploited in targeted attacks against customer-facing deployments. Framework and Tally have confirmed breaches resulting in customer data theft.

The vulnerability allowed attackers to execute arbitrary SQL commands against backend databases without authentication. Both Framework, a laptop manufacturer, and Tally, a financial services provider, disclosed that attackers accessed customer information through their Metabase instances before the vendor issued a patch. The flaw was exploited as a zero-day, meaning attacks occurred before public disclosure or available fixes.

Metabase is widely deployed for data visualization and analytics across sectors including finance, healthcare, and e-commerce. The software connects directly to production databases, making SQL injection flaws particularly dangerous. Organizations using self-hosted Metabase instances were at risk if they had not applied emergency patches released following the attacks.

The rest of this brief is inside the platform

Continue reading. Free.

A free Atlas account unlocks the full briefing, the co-analyst, daily delivery to your inbox, and a sector-personalised feed.

Full brief
Implications, sources, methodology
Co-Analyst
Ask follow-ups on every brief
Sector feed
Briefs filtered to what matters to you
Implications
  • 01Organizations running self-hosted Metabase must patch immediately or isolate instances from production data
  • 02Framework and Tally customers face potential identity theft and fraud from exposed personal information
  • 03Companies using business intelligence tools with direct database access should audit connection privileges
  • 04Incident response teams should review Metabase logs for indicators of SQL injection attempts
Source
BleepingComputer
https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
Brief is editorial commentary by Atlas Intelligence based on the cited public reporting. Atlas does not reproduce source text. Verify primary source before action.
#sql injection#zero-day#metabase#data breach#business intelligence#framework
Related Briefs