Last Update: 09/21/2026 at 10:00 PM EST

Metabase Breach Exposes Connected Customer Data

Coverage from Startup Fortune, VideoCardz, and others

Metabase Breach Exposes Connected Customer Data topic image

Attackers exploited a critical, unauthenticated Metabase vulnerability to gain administrative access and reach databases connected to Metabase instances.

Framework confirmed exposure of customer contact and address data, while other organizations reported exposure involving email addresses, password hashes, cloud records, or access tokens. Metabase patched its cloud service and issued updates and containment guidance for self-hosted deployments, underscoring how analytics tools with broad database access can expand the impact of a single software flaw.

Looking Back
6 Day Timeline
Aug 7Aug 8Aug 9Aug 10Aug 11Aug 12
History
09/09/2026

The update mainly confirms the existing account, adding the vulnerability’s CVE identifier and specifying Metabase’s August 6 disclosure. It does not establish new affected organizations, data categories, or overall scope.

08/24/2026

The incident is now understood as exploitation of a critical, unauthenticated flaw capable of reaching connected databases and services, not merely compromising Metabase itself. The reported scope has broadened to multiple organizations and self-hosted deployments, while CISA has formally listed the vulnerability as actively exploited.

All Articles16 articles
Important6 articles · CI Score 60 and above
Startup Fortune / Judith Murphy
Framework disclosed on August 6 that attackers accessed customer records through a compromised Metabase analytics environment.
8/10/2026 • Data Breaches & Exposure Events • General
VideoCardz
Framework notified customers on August 6 after attackers accessed Framework's Metabase instance through a critical Metabase Cloud SQL injection vulnerability.
8/9/2026 • Data Breaches & Exposure Events • General
Tech My Money / Michael John-Anyaehie
Framework reported on August 6 that a Metabase Cloud zero-day exposed customer contact data in Framework's affected business-intelligence instance.
8/8/2026 • Data Breaches & Exposure Events • General
Help Net Security / Zeljka Zorz
Metabase disclosed on August 6, 2026, that attackers exploited a zero-day SQL injection vulnerability in Metabase Cloud, exposing customer data at Framework, Tally, and Kilo Code.
8/10/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Mayank Parmar
Metabase disclosed active exploitation of a critical SQL injection vulnerability, prompting customer-data investigations at Framework, Tally, and LexisNexis after compromised instances were accessed on August 3.
8/7/2026 • Data Breaches & Exposure Events • General
Engadget / Ian Carlos Campbell
Framework notified customers on August 6 that a Metabase breach detected August 3 at the database provider exposed customer contact, address, and login IP data.
8/7/2026 • Data Breaches & Exposure Events • General
Interesting10 articles · CI Score 45–59
Tech Times / Clayton Lewis
Attackers exploited CVE-2026-72898 in self-hosted Metabase installations from August 2 through August 6, 2026, breaching five companies and exposing personal information and credentials.
8/12/2026 • Data Breaches & Exposure Events • General
SC World
Framework notified customers after attackers exploited a Metabase zero-day vulnerability to access and steal personal data from Framework's cloud instance.
8/10/2026 • Data Breaches & Exposure Events • General
Notebookcheck
Framework notified customers on August 6 that a Metabase vulnerability exposed customer information and potentially database credentials through compromised Metabase Cloud infrastructure.
8/9/2026 • Data Breaches & Exposure Events • General
The Tech Buzz
Framework recently disclosed unauthorized access to its customer database, exposing names, contact details, and physical addresses while payment information remained unaffected.
8/7/2026 • Data Breaches & Exposure Events • General
How-To Geek
Framework notified customers on August 6 that a Metabase breach in an unspecified location exposed personal information after attackers exploited an SQL-oriented zero-day vulnerability on August 3.
8/7/2026 • Data Breaches & Exposure Events • General
Linus Tech Tips
Metabase notified Framework on August 6, 2026, that a zero-day attack on Metabase Cloud exposed Framework customer contact information and triggered remediation efforts.
8/7/2026 • Data Breaches & Exposure Events • General
Zeli
Metabase disclosed a Metabase Cloud zero-day attack on August 3 after attackers accessed customer instances, while Framework notified affected customers within six hours.
8/7/2026 • Data Breaches & Exposure Events • General
CNET / Ajay Kumar
Framework disclosed a customer data breach involving contact, address, and IP information after an attacker exploited a vulnerability in Metabase Cloud.
8/9/2026 • Data Breaches & Exposure Events • General
TechCrunch / Lorenzo Franceschi-Bicchierai
Framework notified all customers after attackers exploiting a Metabase zero-day accessed Framework's cloud instance and stole contact information and physical addresses.
8/7/2026 • Data Breaches & Exposure Events • General
SC World
Framework notified customers after attackers exploited a Metabase zero-day vulnerability to access Framework's cloud instance and expose personal information through Metabase cloud servers.
8/10/2026 • Data Breaches & Exposure Events • General