← Framework

2026 Framework — Metabase SQLi zero-day; customer names/emails/addresses/phones stolen (Aug 3)

2026 Unknown records affected Share on X

Data compromised

Full names, email addresses, login IP addresses, billing and shipping addresses, phone numbers, and company name. Framework for Business customers: company name, phone, VAT, EIN, billing email. Payment card data not obtained per company notice. Customer count unpublished — recordsAffected 0.

Technical writeup

Company-confirmed third-party analytics breach — On August 6, 2026 Framework notified all customers that attackers had accessed its Metabase instance on August 3 via a then-unknown SQL injection vulnerability that Metabase disclosed the same week (critical, CVSS 10.0; unauthenticated SQLi via /api/session/reset_password leading to admin access and theft of connected-database credentials/data). Stolen fields per Framework’s notice shared with BleepingComputer: full names, emails, login IPs, billing/shipping addresses, phone numbers, and company name; business customers may also have VAT, EIN and billing email exposed. Framework said payment information was not obtained, credentials for systems beyond Metabase were rotated, and it saw no admin-control changes outside Metabase. Metabase Cloud customers were auto-patched; self-hosted instances required manual upgrades (safe floors include 0.58.24 through 0.63.5 branches). Headcount unpublished — Framework told “all customers,” so exposure is company-wide pending a numeric census. Separate from the January 2024 Keating Consulting phishing breach (framework2024).

Root cause

Unauthenticated SQL injection zero-day in Metabase (versions ≥1.58 / Cloud SaaS and self-hosted); attackers accessed Framework’s Metabase instance on August 3, 2026. Metabase notified Framework August 6. Distinct from Framework’s 2024 Keating accountant-phishing incident.

References