Metabase CVSS 10 SQL Injection Zero-Day Hits Admin Access

The Metabase CVSS 10 SQL injection zero-day gives attackers admin access and every connected database credential. Framework and Tally already hit.

The Metabase CVSS 10 SQL injection zero-day lets an unauthenticated attacker turn a self-hosted analytics dashboard into a master key for every database it touches. Active exploitation began August 3, 2026, and two named victims — Framework and Tally — have already confirmed customer data theft. If your organization runs Metabase for internal reporting, this…

Read More