Unauthenticated SQL Injection Zero-Day in Metabase (CVSS 10.0, GHSA-vwf4-m7j8-wcjf) Exploited to Steal Framework, Tally, and LexisNexis Customer Data — Threadlinqs Intelligence
As of 2026-08-10, Unauthenticated SQL Injection Zero-Day in Metabase (CVSS 10.0, GHSA-vwf4-m7j8-wcjf) Exploited to Steal Framework, Tally, and LexisNexis Customer Data is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 10 indicators of compromise.
Threat ID: TL-2026-1974 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
An unauthenticated SQL injection zero-day in Metabase's POST /api/session/reset_password endpoint (versions 0.58.0-0.63.3, branded 1.58 and above, both Cloud and self-hosted) let attackers inject
Metabase, a widely deployed open-source and SaaS business-intelligence (BI) platform, disclosed a maximum-severity (CVSS 10.0) unauthenticated SQL injection vulnerability tracked as GHSA-vwf4-m7j8-wcjf. The flaw lives in the publicly reachable POST /api/session/reset_password endpoint: an attacker with no credentials can inject arbitrary SQL into the Metabase application database. By manipulating database records through this injection, the attacker can promote their own session or account to instance administrator, entirely bypassing authentication. Vulnerable releases span every branch from 0.58.0 through 0.63.3 (publicly versioned 1.58 and above), across both Metabase Cloud and self-hosted deployments; versions below 58 are unaffected. GHSA-vwf4-m7j8-wcjf gives slightly narrower per-branch affected ranges (0.58.0-0.58.22, 0.59.0-0.59.19, 0.60.0-0.60.15, 0.61.0-0.61.9, 0.62.0-0.62.7, 0.63.0-0.63.2) which this research treats as the authoritative boundary alongside the vendor's own 0.58.0-0.63.3 framing.
Once an attacker holds instance-admin privileges, Metabase's own design makes the blast radius severe: the application stores the connection credentials for every database a customer has wired into it for reporting and analytics. With admin access, the attacker can change application configuration, read those stored credentials, and use them to query connected production databases directly through Metabase's own established connections -- the resulting queries arrive at the downstream database from the legitimate, expected application account, indistinguishable from normal Metabase traffic. There is no malware payload or foreign network indicator to catch, only a distinctive HTTP log signature: a POST to /api/session/reset_password returning HTTP 400 immediately followed by a GET to /api/user/current returning HTTP 200 from the same source/session -- Metabase states plainly that finding this pattern in application or ingress logs means the instance was likely compromised.
Metabase confirmed active exploitation against its own Cloud infrastructure beginning on or before 2026-08-03. On 2026-08-06 Metabase notified Framework, a modular-laptop manufacturer, that its Cloud instance had been vulnerable and accessed; Framework in turn confirmed exposure of customer names, email addresses, phone numbers, physical addresses, login IP addresses, and (for Framework for Business accounts) company names, VAT/EIN numbers, and billing emails -- order and payment data were not affected, and Framework stated the breach affected all customers while it rotated database credentials and engaged third-party forensics. Tally, an online form-builder, confirmed its Metabase analytics environment was compromised the same day the attack began (2026-08-03), with the attacker reaching customer email addresses and password hashes ('password as a cryptographic hash'), though form content and submitted responses were not reached because they are stored separately from the analytics environment. LexisNexis confirmed 'unusual activity on servers that are hosted and managed by a third-party vendor' affecting its Metabase API integration and disconnected the affected systems to contain the issue; the specific scope of any customer-data exposure remains under investigation as of publication and is unrelated to LexisNexis's separate, earlier 2026 AWS/React2Shell breach. No further named victims beyond Framework, Tally, and LexisNexis appear across vendor, wire-service, or independent security-research coverage as of 2026-08-10, and none of the sources reviewed describe evidence of internet-wide scanning for exposed instances -- exploitation is documented only against Metabase's own Cloud-hosted fleet.
No CVE identifier has been assigned to this vulnerability; it is tracked solely via the GitHub Security Advisory GHSA-vwf4-m7j8-wcjf, published 2026-08-06 by GitHub user perivamsi, with no CWE classification listed on the advisory itself (CWE-89 SQL Injection is
Target sectors: technology, software business intelligence, consumer electronics, legal and data analytics services, online forms and surveys
Target regions: Global
Timeline
- Attacker begins exploiting the unauthenticated SQL injection in POST /api/session/reset_password against Metabase Cloud, gaining instance-admin access without credentials; Tally's Metabase analytics environment is compromised the same day.
- Metabase detects active exploitation against its Cloud platform during the attack.
- Metabase notifies Framework at 9:00 AM PT that its Cloud instance had been vulnerable and was accessed by the attacker.
- GitHub Security Advisory GHSA-vwf4-m7j8-wcjf is published by perivamsi, detailing the flaw, the CVSS 10.0 score, affected versions 0.58.0-0.63.3, and patched releases.
- Metabase publishes its 'Security Update' blog post, ships patched versions (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, 0.63.5), and blocks the abused endpoint across its own Cloud fleet; all Cloud customers are automatically upgraded.
- BleepingComputer publishes 'Framework, Tally disclose Metabase data theft attacks,' confirming both companies' breach notifications and that no CVE identifier has been assigned.
- Tally notifies its customers that its Metabase analytics environment was compromised, exposing email addresses and password hashes; forms and submitted responses were not reached because they are stored separately.
- Clever Cloud, a PaaS hosting provider for managed Metabase deployments, blocks the /api/session/reset_password endpoint for its customers per its security changelog.
- Independent security researchers (hard2bit, Security Affairs) publish technical analyses characterizing the flaw as a third-party/supply-chain BI risk and detailing the credential-theft-then-query exploitation chain.
- Framework emails affected customers disclosing exposure of names, emails, phone numbers, addresses, and login IPs (order and payment data unaffected), states the breach affected all customers, and confirms it rotated database credentials and engaged third-party forensics; The Register publishes coverage of the disclosure.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 10 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, T1190, T1199, T1098, T1098, T1078, T1552, T1538, T1213, T1567