2026 Framework — Metabase SQLi zero-day; customer names/emails/addresses/phones stolen (Aug 3)
Data compromised
Full names, email addresses, login IP addresses, billing and shipping addresses, phone numbers, and company name. Framework for Business customers: company name, phone, VAT, EIN, billing email. Payment card data not obtained per company notice. Customer count unpublished — recordsAffected 0.
Technical writeup
Company-confirmed third-party analytics breach — On August 6, 2026 Framework notified all customers that attackers had accessed its Metabase instance on August 3 via a then-unknown SQL injection vulnerability that Metabase disclosed the same week (critical, CVSS 10.0; unauthenticated SQLi via /api/session/reset_password leading to admin access and theft of connected-database credentials/data). Stolen fields per Framework’s notice shared with BleepingComputer: full names, emails, login IPs, billing/shipping addresses, phone numbers, and company name; business customers may also have VAT, EIN and billing email exposed. Framework said payment information was not obtained, credentials for systems beyond Metabase were rotated, and it saw no admin-control changes outside Metabase. Metabase Cloud customers were auto-patched; self-hosted instances required manual upgrades (safe floors include 0.58.24 through 0.63.5 branches). Headcount unpublished — Framework told “all customers,” so exposure is company-wide pending a numeric census. Separate from the January 2024 Keating Consulting phishing breach (framework2024).
Root cause
Unauthenticated SQL injection zero-day in Metabase (versions ≥1.58 / Cloud SaaS and self-hosted); attackers accessed Framework’s Metabase instance on August 3, 2026. Metabase notified Framework August 6. Distinct from Framework’s 2024 Keating accountant-phishing incident.
References
- https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
- https://www.metabase.com/blog/security-update
- https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
- https://www.howtogeek.com/framework-pc-customer-data-breach/
- https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf