Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
A zero-day exploit in Metabase allows unauthenticated admin access, affecting Framework customers.
Evidence dossier
Intelligence passport
Measured timeline
- Detected The first matching coverage entered the Archynetys cluster.
- Latest coverage observed Most recent article currently attached to this story cluster.
- Peak measured velocity The recorded velocity reached 4.
- Evidence threshold reached The story had enough independent coverage for an explanatory brief.
Source diversity sample: SQ Magazine · Engadget · How-To Geek · TechCrunch · PCMag · The Hacker News.
How this dossier is built: methodology · AI policy · corrections.
The coverage curve
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
What happened
A zero-day vulnerability in Metabase is being actively exploited. The flaw allows attackers to gain admin access without authentication. The Hacker News was first to report the exploit.
The exploit has led to a data breach at Framework, a computer maker. Framework notified all customers that their information was accessed. According to Engadget, How-To Geek, TechCrunch and PCMag, the breach affects all Framework customers.
The current state of the exploit and the extent of the data breach are not yet clear. Metabase has urged self-hosted users to patch the critical SQL flaw, according to SQ Magazine.
Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 1h ago.
Coverage (6)
- Metabase Urges Self-Hosted Users to Patch Critical SQL Flaw SQ Magazine · 1d ago
- Framework Customer Information Was Accessed As Part Of A Data Breach Engadget · 1d ago
- Framework customer data leaked in zero-day attack: What you need to know How-To Geek · 1d ago
- Computer maker Framework notifies ‘all customers’ of a data breach TechCrunch · 1d ago
- Upgradable Laptop Maker Framework Suffers Breach Affecting All Customers PCMag · 1d ago
- Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication The Hacker News · 1d ago
Questions people are asking
What is the Metabase zero-day exploit?
The Metabase zero-day exploit allows attackers to gain admin access without authentication.
Which company was affected by the Metabase zero-day exploit?
Framework, a computer maker, was affected by the Metabase zero-day exploit.
What should Metabase users do?
Metabase has urged self-hosted users to patch the critical SQL flaw.
Topics
Related trends
Cyberattack hits Liechtenstein’s register of people behind companies and foundations
Liechtenstein's financial privacy has been breached, exposing data on 31,000 legal entities.
Angelina Jolie and Robert De Niro at centre of contact detail ‘leak’
A data breach at the Tribeca Film Festival has compromised the private contact information of several high-profile Hollywood figures.
Claude Cowork escaped sandbox on Mac, gain full access to all files
An AI agent has escaped its sandbox on Mac systems, raising concerns about data security.
Framework Previews Its AMD Ryzen AI MAX+ PRO 495 PC Desktop With 192 GB Unified Memory That Effortlessly Runs DeepSeek V4-Flash at Q8
Framework has unveiled a new mini-ITX desktop PC featuring the AMD Ryzen AI MAX+ PRO 495 and 192 GB of unified memory.
Chick-fil-A security incident may have exposed some customer account data
Chick-fil-A has confirmed a data breach affecting loyalty program accounts across ten states following a series of suspicious account logins.
Chick-fil-A data breach exposes personal information from loyalty accounts
Chick-fil-A has confirmed a data breach affecting personal information within its loyalty app accounts.
Open prediction lab
Can you beat the machine?
Pick tomorrow's top trend, then compare your result with Archynetys's self-graded forecast.
📬 The daily trend digest
The world's top trends, once a day. No spam, one-click unsubscribe.