A critical SQL injection vulnerability in the data analytics platform Metabase has been actively exploited to breach customer instances and steal data. The zero-day flaw carries the maximum CVSS severity score of 10.0 and can give an unauthenticated remote attacker administrator access to a Metabase instance. Metabase disclosed the attacks on Thursday, confirming that its Cloud SaaS platform had been compromised. The company said the vulnerability affects versions 1.58 and above and that self-hosted installations are also vulnerable. Cloud customers have already been patched, while organizations operating self-hosted installations must apply an update manually. After gaining administrator access, attackers can change application settings, steal stored credentials for connected databases, read accessible data, and export it. Metabase recommends that self-hosted customers upgrade immediately, revoke active user sessions, review API keys and administrator accounts, rotate connected-database credentials, and inspect logs and query history. Organizations unable to update immediately should temporarily block access to the “/api/session/reset_password” endpoint. Laptop maker Framework confirmed that attackers accessed its Metabase instance on August 3 and stole information including customer names, email addresses, login IP addresses, phone numbers, and billing and shipping details. Online form builder Tally also notified users that its Metabase analytics environment was compromised on August 3. Attackers obtained email addresses and cryptographically hashed passwords, but did not reach users’ forms or submitted answers. LexisNexis separately reported disruption to services including its Metabase API after unusual activity was detected on servers managed by a third-party vendor; it remains unclear whether customer data was exposed. Administrators in Somalia running self-hosted Metabase installations should update promptly, rotate connected-database credentials, and examine their logs for evidence that their systems may have been compromised.