Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen
Zero-day vulnerability in internal tools: What the Metabase incident has triggered
Compliance & Standards

Zero-day vulnerability in internal tools: What the Metabase incident has triggered

A critical zero-day in Metabase hit Framework and Tally. What an exposed internal tool means for GDPR obligations and audit evidence.

4 min read read
ISO 27001 Lead Auditor (PECB/TÜV) T.I.S.P. (TeleTrusT) ITIL 4 (PeopleCert) BSI IT-Grundschutz-Praktiker (DGI) Ext. ISB (TÜV) BSI CyberRisikoCheck CEH (EC-Council)

Beitragsbild KI-generiert, redaktionell geprüft (EU AI Act Art. 50).

TL;DR

On 3 August 2026, a critical SQL injection vulnerability in Metabase was actively exploited. Personal data was leaked from two companies. Operators must update their systems immediately and check whether they are required to report the incident under the GDPR.

Table of Contents (6 sections)

What is a zero-day vulnerability?

A zero-day vulnerability is a security vulnerability that attackers are already exploiting, whilst the vendor has not yet released a patch. Organisations have literally zero days to prepare. This becomes particularly critical when the affected tool is operated in-house and the scope of its database access has never been documented.

What happened during the Metabase incident on 3 August 2026

On 3 August 2026, Metabase identified active attacks on cloud-based and self-hosted installations. The cause was an unauthenticated SQL injection, rated with a CVSS Base score of 10.0 and a Temporal Score of 9.5 (CERT-Bund WID-SEC-2026-2715, no CVE ID assigned). Attackers injected SQL commands via the password reset endpoint and gained access to stored database credentials for all connected databases.

In the case of the laptop manufacturer Framework, the data compromised included name, email address, telephone number, login IP address, and billing and delivery addresses, including company name. Order and payment details were not accessed. Investigations are still ongoing to determine whether tax identification numbers for business customers are also affected. In the case of the form service Tally, email addresses and password hashes were affected; forms and responses remained unaffected as they were stored separately.

Indicator of Compromise: POST /api/session/reset_password with HTTP status 400, immediately followed by GET /api/user/current with HTTP status 200. This combination in the application and ingress logs of the Metabase server identifies the attack.

Versions in the 0.58 to 0.63 families are affected. Sources report this differently (heise: “58 to 63”; CERT-Bund: < x.58.24), but are referring to the same version family. Confirmed minimum versions: 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, 0.63.5.

Why internal analytics tools are an underestimated attack surface

Following a successful attack, the configuration, stored database credentials and all data accessible via these become accessible to the attacker. Following the incident, Framework had to review what data external analytics platforms were receiving. The company plans to restrict their access to only the database columns that are actually required.

Self-hosted BI and monitoring tools with broad database access are easily overlooked in regular security cycles. Without an entry in the asset inventory, they are not included in patch management processes. This week’s Metabase incident was not an isolated case. On 7 August 2026, CISA added CVE-2026-8037 to its catalogue of known-exploited vulnerabilities: an unauthenticated command injection in Progress Kemp LoadMaster (CVSS 9.6). 792 exploit attempts originating from 65 IP addresses over 41 days demonstrate just how systematically such vulnerabilities are being exploited.

Immediate measures for Metabase operators

  1. Update to a secure minimum version: 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 or 0.63.5.
  2. If an immediate update is not possible: Block access to /api/session/reset_password at the reverse proxy or in the firewall.
  3. Revoke all active user sessions.
  4. Check API keys and administrator accounts for unauthorised changes.
  5. Rotate the access credentials for all connected databases.
  6. Review application and ingress logs for IoC patterns.

A vulnerability scan reveals internally operated services of this kind before an attacker finds them.

Notification Obligations and GDPR Evidence

For organisations that operate their own Metabase instances and process personal data as part of that operation, two sets of obligations apply directly.

Article 32(1)(d) of the GDPR requires a procedure for regularly reviewing the effectiveness of technical and organisational measures. Any tool missing from the asset inventory falls outside the scope of this procedure. Organisations that establish this evidence in a structured manner through a security consultancy have a robust basis for dealing with supervisory authorities and internal audits.

Article 33 of the GDPR: If personal data is leaked, there is generally a 72-hour reporting deadline to the competent supervisory authority. The notification obligation does not apply if the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The deadline begins when the breach becomes known, not when the investigation is concluded. Framework has informed the supervisory authorities and commissioned an IT forensic investigation.

Assessment

The Metabase zero-day incident reveals a structural pattern: unauthenticated access to an internally operated tool with broad database access, which was not covered by the regular security cycle. By engaging forensic experts and supervisory authorities, Framework has fulfilled its obligations. Anyone wishing to prepare for this process will find a methodological introduction in the Practical Guide to Vulnerability Management.

Next Step

Our certified security experts will advise you on the topics covered in this article — free and without obligation.

Free · 30 minutes · No obligation

Share this article

Certified ISO 27001ISO 9001AZAV

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen