ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

Metabase SQL injection allowed data-theft attacks on customer instances

Source headline: Metabase SQLi zero-day exploited in customer data-theft attacks

Threat level Critical
Signal strength 80/100
Source confidence 1 source
Published 3 hours ago

Intelligence Summary

A critical SQL injection in Metabase was reportedly exploited in zero-day attacks. The activity targeted customer Metabase instances to steal data. Affected deployments were associated with organizations such as Framework and Tally. The flaw is particularly risky because it enables unauthorized database queries through the application layer. Users running Metabase should prioritize patching and validate exposure of Metabase endpoints to the internet.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#zero-day #data-theft #customer-instances #metabase #sqli
Original reporting BleepingComputer Metabase SQLi zero-day exploited in customer data-theft attacks
Open original source