← Back to Tech & Science

Critical Metabase Vulnerability Exploited in Breaches of Framework and Tally

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SAN FRANCISCO — A critical, unauthenticated SQL injection vulnerability in the popular business intelligence platform Metabase has been actively exploited to breach customer instances at several major technology firms, including laptop manufacturer Framework and financial software company Tally. The attack vector targets versions 1.58 and later of the open-source analytics tool, allowing unauthorized actors to inject malicious code directly into database queries without requiring login credentials.

The exploitation was confirmed on August 7, 2026, following reports that attackers had successfully accessed sensitive customer data and stolen internal administrative credentials from compromised systems. The vulnerability allows threat actors to execute arbitrary SQL commands against the underlying databases connected to Metabase instances, effectively granting them full read access to stored information.

Framework, known for its modular laptop designs, disclosed that unauthorized parties gained entry to their analytics environment through the flaw. Similarly, Tally reported a breach of its data infrastructure linked to the same vulnerability. Both organizations have initiated emergency response protocols to contain the intrusion and assess the scope of potential data exfiltration. The specific volume of compromised records remains under investigation.

Metabase administrators identified the issue as a zero-day exploit, meaning no patch was publicly available at the time of the initial attacks. The flaw resides in how certain versions of the software process user input within SQL queries, failing to properly sanitize parameters before execution. This oversight permits attackers to manipulate database interactions and extract information that should remain secured.

Security researchers noted that the attack method requires no prior authentication, making any exposed Metabase instance running vulnerable versions an immediate target for automated scanning tools. The widespread adoption of Metabase across enterprise environments has amplified the potential impact of this single vulnerability, raising concerns about similar breaches at other undisclosed organizations.

As of late August 7, neither Framework nor Tally had specified whether customer personally identifiable information was among the stolen assets or if financial data was accessed. Both companies are working with cybersecurity firms to secure their networks and notify affected parties as details emerge. Metabase has since released an emergency patch addressing the SQL injection flaw, urging all users of versions 1.58 through the latest release to update immediately.

Questions remain regarding the identity of the attackers behind the coordinated exploitation efforts. While no group has claimed responsibility for the breaches targeting Framework and Tally, security analysts warn that the simplicity of the exploit suggests it could be leveraged by various threat actors with minimal technical expertise. The investigation into whether other organizations were targeted during this window continues as companies worldwide audit their Metabase deployments.

Discussion

0 / 2000