Unauthenticated Metabase SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf) Exploited to Steal Framework and Tally Customer Data — Threadlinqs Intelligence
As of 2026-08-07, Unauthenticated Metabase SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf) Exploited to Steal Framework and Tally Customer Data is a critical-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 12 indicators of compromise.
Threat ID: TL-2026-1937 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: DATA_BREACH
A critical unauthenticated SQL injection zero-day in Metabase (Cloud and self-hosted, versions 1.58 and above) let attackers inject arbitrary SQL via the /api/session/reset_password endpoint to gain
On August 3, 2026, Metabase identified an attack against its Cloud infrastructure exploiting a previously unknown (zero-day), unauthenticated SQL injection vulnerability in the `/api/session/reset_password` endpoint. The flaw, tracked as GHSA-vwf4-m7j8-wcjf (CVSS 3.1: 10.0, no CVE assigned as of disclosure), allows a remote, unauthenticated attacker to inject arbitrary SQL into the Metabase application database. Exploitation grants administrator access to the Metabase instance, from which an attacker can modify application configuration, harvest stored credentials for every database connected to that instance, read any data reachable through those connections, and export it. The distinctive attack signature is a `POST /api/session/reset_password` request returning HTTP 400 immediately followed by a `GET /api/user/current` request returning HTTP 200 — indicating a successfully forged administrative session. Metabase CEO Sameer Al-Sakran publicly confirmed the Cloud platform was attacked using this unknown vulnerability.
The vulnerability affects self-hosted Metabase versions 1.58.0 and above (all point releases prior to 1.58.24, 1.59.21, 1.60.17, 1.61.11, 1.62.9, and 1.63.5 depending on major branch; versions below 58 are unaffected). Metabase Cloud was also actively exploited prior to disclosure but has since been patched vendor-side, with Metabase additionally blocking the vulnerable endpoint at the infrastructure level as a containment measure — no customer action is required for Cloud tenants. Metabase publicly disclosed the advisory and shipped patches on August 6, 2026, notifying affected Cloud customers (including Framework) the same day.
Post-exploitation activity against at least one victim instance followed a tight, methodical timeline consistent with scripted rather than manual access: the attacker obtained an authenticated administrator session at 13:00, ran 54 queries against connected data sources between 13:00 and 13:12, created a Metabase API key tied to a service account at 13:14 to establish a secondary persistence/access path, ran 19 further queries through that key between 13:14 and 13:17, and deleted the API key at 13:17 — an apparent anti-forensic cleanup step removing the persistence artifact immediately after use. The query pattern has been characterized as semi-random scanning across tables rather than targeting specific pre-identified records, suggesting opportunistic rather than pre-planned data collection once admin access was obtained.
Framework, a laptop and modular-PC manufacturer, confirmed on August 7, 2026 that attackers exfiltrated customer names, login and billing email addresses, login IP addresses, billing/shipping addresses, phone numbers, and company/tax information (VAT, EIN, billing email) for business customers via its compromised Metabase Cloud instance; payment and order data were not affected. Framework told customers the breach affected all of them but declined to disclose an exact count. Tally, a form-builder SaaS, confirmed that attackers accessed user email addresses and one-way password hashes via its Metabase analytics instance; Tally stated that form content and submission data are stored separately and were not accessed. LexisNexis, a legal/data-analytics provider, took systems offline and engaged an external forensic firm to investigate possible exposure tied to this Metabase compromise; as of disclosure it remained unclear whether LexisNexis customer data was accessed. (This Metabase-linked LexisNexis exposure is a separate, unrelated event from LexisNexis Legal & Professional's earlier March 2026 breach involving different infrastructure.) No CVE identifier, public proof-of-concept exploit code, or threat-actor attribution had been published for this incident as of disclosure.
Target sectors: technology, hardwaremanufacturing, softwaresaas, legalservices
Target regions: North America, Global
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 12 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, CRITICAL, threat intelligence, cybersecurity, T1588.006, T1190, T1199, T1098.001, T1550.004, T1552, T1213, T1567, T1020