Threat reportData BreachTL-2026-1937

Unauthenticated Metabase SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf) Exploited to Steal Framework and Tally Customer Data

criticalACTIVE

Unauthenticated Metabase SQL Injection Zero-Day (TL-2026-1937), also tracked as GHSA-vwf4-m7j8-wcjf, is a critical-severity data breach scored CVSS 10, first published 2026-08-07. It has no confirmed attribution, affects Metabase, Inc. Metabase (self-hosted / Open Source / Enterprise), maps to 9 MITRE ATT&CK techniques (T1020, T1098.001, T1190), and is covered by 9 detection rules and 12 indicators of compromise.

CVSS
10/10Critical
CVEs
0None referenced
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-1937

Threat ID
TL-2026-1937
Also known as
GHSA-vwf4-m7j8-wcjf
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, hardwaremanufacturing, softwaresaas, legalservices
Target regions
North America, Global
Detection rules
9
Indicators of compromise
12

How Unauthenticated Metabase SQL Injection Zero-Day works

A critical unauthenticated SQL injection zero-day in Metabase (Cloud and self-hosted, versions 1.58 and above) let attackers inject arbitrary SQL via the /api/session/reset_password endpoint to gain administrator access and exfiltrate data. Laptop maker Framework and form-builder Tally both confirmed customer data theft from compromised Metabase instances; LexisNexis took systems offline pending investigation. Metabase has shipped patched releases and Cloud is already remediated.

On August 3, 2026, Metabase identified an attack against its Cloud infrastructure exploiting a previously unknown (zero-day), unauthenticated SQL injection vulnerability in the `/api/session/reset_password` endpoint. The flaw, tracked as GHSA-vwf4-m7j8-wcjf (CVSS 3.1: 10.0, no CVE assigned as of disclosure), allows a remote, unauthenticated attacker to inject arbitrary SQL into the Metabase application database. Exploitation grants administrator access to the Metabase instance, from which an attacker can modify application configuration, harvest stored credentials for every database connected to that instance, read any data reachable through those connections, and export it. The distinctive attack signature is a `POST /api/session/reset_password` request returning HTTP 400 immediately followed by a `GET /api/user/current` request returning HTTP 200 — indicating a successfully forged administrative session. Metabase CEO Sameer Al-Sakran publicly confirmed the Cloud platform was attacked using this unknown vulnerability.

The vulnerability affects self-hosted Metabase versions 1.58.0 and above (all point releases prior to 1.58.24, 1.59.21, 1.60.17, 1.61.11, 1.62.9, and 1.63.5 depending on major branch; versions below 58 are unaffected). Metabase Cloud was also actively exploited prior to disclosure but has since been patched vendor-side, with Metabase additionally blocking the vulnerable endpoint at the infrastructure level as a containment measure — no customer action is required for Cloud tenants. Metabase publicly disclosed the advisory and shipped patches on August 6, 2026, notifying affected Cloud customers (including Framework) the same day.

Post-exploitation activity against at least one victim instance followed a tight, methodical timeline consistent with scripted rather than manual access: the attacker obtained an authenticated administrator session at 13:00, ran 54 queries against connected data sources between 13:00 and 13:12, created a Metabase API key tied to a service account at 13:14 to establish a secondary persistence/access path, ran 19 further queries through that key between 13:14 and 13:17, and deleted the API key at 13:17 — an apparent anti-forensic cleanup step removing the persistence artifact immediately after use. The query pattern has been characterized as semi-random scanning across tables rather than targeting specific pre-identified records, suggesting opportunistic rather than pre-planned data collection once admin access was obtained.

Framework, a laptop and modular-PC manufacturer, confirmed on August 7, 2026 that attackers exfiltrated customer names, login and billing email addresses, login IP addresses, billing/shipping addresses, phone numbers, and company/tax information (VAT, EIN, billing email) for business customers via its compromised Metabase Cloud instance; payment and order data were not affected. Framework told customers the breach affected all of them but declined to disclose an exact count. Tally, a form-builder SaaS, confirmed that attackers accessed user email addresses and one-way password hashes via its Metabase analytics instance; Tally stated that form content and submission data are stored separately and were not accessed. LexisNexis, a legal/data-analytics provider, took systems offline and engaged an external forensic firm to investigate possible exposure tied to this Metabase compromise; as of disclosure it remained unclear whether LexisNexis customer data was accessed. (This Metabase-linked LexisNexis exposure is a separate, unrelated event from LexisNexis Legal & Professional's earlier March 2026 breach involving different infrastructure.) No CVE identifier, public proof-of-concept exploit code, or threat-actor attribution had been published for this incident as of disclosure.

MITRE ATT&CK techniques used in TL-2026-1937

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Persistence

T1098.001 Additional Cloud Credentials

Initial Access

T1190 Exploit Public-Facing Application; T1199 Trusted Relationship

Collection

T1213 Data from Information Repositories

lateral-movement

T1550.004 Web Session Cookie

Credential Access

T1552 Unsecured Credentials

Resource Development

T1588.006 Vulnerabilities

Affected products and versions in Unauthenticated Metabase SQL Injection Zero-Day

  • Metabase, Inc. — Metabase (self-hosted / Open Source / Enterprise)
    Vulnerable versions: 1.58.0-1.58.23; 1.59.0-1.59.19; 1.60.0-1.60.15; 1.61.0-1.61.9; 1.62.0-1.62.7; 1.63.0-1.63.2
    Fixed in: 1.58.24; 1.59.21; 1.60.17; 1.61.11; 1.62.9; 1.63.5
  • Metabase, Inc. — Metabase Cloud
    Vulnerable versions: All Cloud tenants prior to vendor-side patch; exploited in the wild before public disclosure
    Fixed in: All Cloud tenants — vendor-patched and endpoint-blocked, no customer action required

Remediation for Unauthenticated Metabase SQL Injection Zero-Day

Patches

  • 1.58.24
  • 1.59.21
  • 1.60.17
  • 1.61.11
  • 1.62.9
  • 1.63.5
  • Metabase Cloud — already patched vendor-side, no customer action required

Immediate actions

  • Upgrade self-hosted Metabase to the patched release for your major version: 1.58.24, 1.59.21, 1.60.17, 1.61.11, 1.62.9, or 1.63.5
  • Until patched, block all access to POST /api/session/reset_password at the reverse proxy/WAF/load balancer
  • If the reset_password endpoint was publicly reachable, delete all rows from the core_session table to forcibly revoke every active session
  • Review Metabase API keys and revoke any that are unrecognized, including any tied to service accounts you did not create

Workarounds

  • Temporarily block all inbound requests to /api/session/reset_password until the instance is upgraded

Longer-term hardening

  • Audit all administrator accounts for unauthorized creation or modification
  • Rotate credentials for every database connected to the affected Metabase instance
  • Review connected data-warehouse/database access logs for unauthorized queries during the exposure window
  • Review Metabase activity and query history for suspicious admin-level actions, including short-lived API keys created and deleted in the same session
  • Restrict public internet exposure of self-hosted Metabase instances (place behind authentication/VPN/allow-list)

Weaknesses (CWE) in Unauthenticated Metabase SQL Injection Zero-Day

CWE-89

Timeline of Unauthenticated Metabase SQL Injection Zero-Day

  • At 13:17, the attacker deletes the API key created minutes earlier, removing the persistence artifact from the instance.
  • At 13:14, the attacker creates a Metabase API key tied to a service account to establish a secondary access path, then runs 19 further queries through that key between 13:14 and 13:17.
  • Per Framework's disclosed incident timeline, the attacker obtains an authenticated administrator session on the compromised instance at 13:00 and runs 54 queries against connected data sources between 13:00 and 13:12.
  • Metabase identifies an attack against its Cloud infrastructure exploiting a previously unknown (zero-day) unauthenticated SQL injection flaw; Framework's and Tally's Metabase-hosted instances are compromised the same day.
  • At approximately 9:00am Pacific Time, Metabase notifies Framework of the breach affecting its Cloud-hosted Metabase instance.
  • Metabase blocks the vulnerable /api/session/reset_password endpoint at the infrastructure level as an additional containment measure alongside shipping the patched releases.
  • Metabase publicly discloses GHSA-vwf4-m7j8-wcjf (CVSS 10.0), an unauthenticated SQL injection in /api/session/reset_password affecting self-hosted versions 1.58 and above, and ships patched releases (1.58.24, 1.59.21, 1.60.17, 1.61.11, 1.62.9, 1.63.5); Metabase Cloud is confirmed patched.
  • BleepingComputer publishes the first consolidated report naming Framework, Tally, and LexisNexis as organizations affected by the Metabase zero-day.
  • LexisNexis takes systems offline and engages an external forensic firm to investigate possible exposure tied to the Metabase compromise; it remains unclear whether LexisNexis customer data was accessed.
  • Tally discloses that attackers accessed user email addresses and password hashes via the compromised Metabase instance; Tally states form submission data was not accessed.
  • Framework emails 'all customers' disclosing the breach, confirming exposure of names, emails, phone numbers, billing/shipping addresses, login IPs, and company/tax information; payment and order data were not affected.

Sources cited for Unauthenticated Metabase SQL Injection Zero-Day

Detection coverage for TL-2026-1937

As of 2026-08-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1937 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats