Metabase Breach Exposes Connected…Metabase Breach Exposes Connected Customer DataCoverage from Startup Fortune, VideoCardz, and others
00/00/0000
DailyWeekly
Attackers exploited a critical, unauthenticated Metabase vulnerability to gain administrative access and reach databases connected to Metabase instances.
Framework confirmed exposure of customer contact and address data, while other organizations reported exposure involving email addresses, password hashes, cloud records, or access tokens. Metabase patched its cloud service and issued updates and containment guidance for self-hosted deployments, underscoring how analytics tools with broad database access can expand the impact of a single software flaw.
Looking Back
6 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
Aug 7
Aug 8
Aug 9
Aug 10
Aug 11
Aug 12
History
09/09/2026
The update mainly confirms the existing account, adding the vulnerability’s CVE identifier and specifying Metabase’s August 6 disclosure. It does not establish new affected organizations, data categories, or overall scope.
08/24/2026
The incident is now understood as exploitation of a critical, unauthenticated flaw capable of reaching connected databases and services, not merely compromising Metabase itself. The reported scope has broadened to multiple organizations and self-hosted deployments, while CISA has formally listed the vulnerability as actively exploited.
Framework notified customers on August 6 after attackers accessed Framework's Metabase instance through a critical Metabase Cloud SQL injection vulnerability.
8/9/2026 • Data Breaches & Exposure Events • General
Metabase disclosed on August 6, 2026, that attackers exploited a zero-day SQL injection vulnerability in Metabase Cloud, exposing customer data at Framework, Tally, and Kilo Code.
8/10/2026 • Data Breaches & Exposure Events • General
Metabase disclosed active exploitation of a critical SQL injection vulnerability, prompting customer-data investigations at Framework, Tally, and LexisNexis after compromised instances were accessed on August 3.
8/7/2026 • Data Breaches & Exposure Events • General
Framework notified customers on August 6 that a Metabase breach detected August 3 at the database provider exposed customer contact, address, and login IP data.
8/7/2026 • Data Breaches & Exposure Events • General
Attackers exploited CVE-2026-72898 in self-hosted Metabase installations from August 2 through August 6, 2026, breaching five companies and exposing personal information and credentials.
8/12/2026 • Data Breaches & Exposure Events • General
Framework notified customers after attackers exploited a Metabase zero-day vulnerability to access and steal personal data from Framework's cloud instance.
8/10/2026 • Data Breaches & Exposure Events • General
Framework notified customers on August 6 that a Metabase vulnerability exposed customer information and potentially database credentials through compromised Metabase Cloud infrastructure.
8/9/2026 • Data Breaches & Exposure Events • General
Framework recently disclosed unauthorized access to its customer database, exposing names, contact details, and physical addresses while payment information remained unaffected.
8/7/2026 • Data Breaches & Exposure Events • General
Framework notified customers on August 6 that a Metabase breach in an unspecified location exposed personal information after attackers exploited an SQL-oriented zero-day vulnerability on August 3.
8/7/2026 • Data Breaches & Exposure Events • General
Metabase notified Framework on August 6, 2026, that a zero-day attack on Metabase Cloud exposed Framework customer contact information and triggered remediation efforts.
8/7/2026 • Data Breaches & Exposure Events • General
Metabase disclosed a Metabase Cloud zero-day attack on August 3 after attackers accessed customer instances, while Framework notified affected customers within six hours.
8/7/2026 • Data Breaches & Exposure Events • General
Framework disclosed a customer data breach involving contact, address, and IP information after an attacker exploited a vulnerability in Metabase Cloud.
8/9/2026 • Data Breaches & Exposure Events • General
Framework notified all customers after attackers exploiting a Metabase zero-day accessed Framework's cloud instance and stole contact information and physical addresses.
8/7/2026 • Data Breaches & Exposure Events • General
Framework notified customers after attackers exploited a Metabase zero-day vulnerability to access Framework's cloud instance and expose personal information through Metabase cloud servers.
8/10/2026 • Data Breaches & Exposure Events • General