#metabase — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #metabase, aggregated by home.social.
-
🚨 CRITICAL ALERT: CVE-2026-72898 (CVSS 10.0)
Unauthenticated SQL Injection in Metabase allows remote attackers to execute arbitrary SQL, hijack admin accounts & exfiltrate enterprise DB credentials. Patch immediately!
Read full analysis: https://denizhalil.com/2026/08/13/cve-2026-72898-metabase-unauthenticated-sql-injection/
-
7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase
This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
What ...
Continued 👉 #selfhosting #selfhosted #vps #proxyserver #reverseproxy #jre #openjdk #installguide #letsencrypt #debian
7 Steps to Easily Configure Op... -
#LexisNexis shuts down services after suspicious activity on servers
#Diligence #Metabase #Newsdesk #privacy #DataBroker #cybersecurity
-
#Metabase #SQLi zero-day exploited in customer data-theft attacks
https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/
-
7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase
This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
What is OpenLiteSpeed?
OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you to ...
Continued 👉 https://blog.radwebhosting.com/configure-openlitespeed-as-a-reverse-proxy-for-metabase/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #selfhosted #debian #reverseproxy #openjdk #letsencrypt #jre #selfhosting #installguide #proxyserver #vps -
-
Title: Computer maker #Framework notifies ‘all customers’ of a data breach
Link: https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
-
Ein Zero-Day in #Metabase führte zu einem Datenleck beim Laptophersteller #Framework Kundenkontakte sowie Lieferdaten gingen verloren Zahlungs- und Bestellinformationen blieben laut Hersteller geschützt Metabase hat Updates bereitgestellt und Cloud-Instanzen gesichert https://www.heise.de/news/Durch-Metabase-0day-Datenleck-bei-Laptophersteller-Framework-11403050.html?seite=all
-
Computer maker #Framework notifies ‘all customers’ of a #DataBreach
https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
-
Durch #Metabase - #0day: #Datenleck bei Laptophersteller #Framework ( @frameworkcomputer ) | Security https://www.heise.de/news/Durch-Metabase-0day-Datenleck-bei-Laptophersteller-Framework-11403050.html #Datenschutz #privacy #DataLeak #phishing #Patchday #ZeroDay
-
Good news: I’m learning which services use #Metabase (which I really like!) as they send out breach notifications to customers.
Bad news: Using a third-party analytics tool can be great, but maybe don’t give it access to things like your user account tables with emails and hashed passwords (or worse)?
-
Notebook-Hersteller #Framework hat einen #Datenschutzvorfall erlitten. Seine Business-Intelligence-Datenbank wurde beim Anbieter #Metabase über einen 0-Day gehackt und es sind #Kundendaten abgeflossen.
https://borncity.com/blog/2026/08/07/datenschutzvorfall-bei-laptop-hersteller-framework-august-2026/
-
Just got a notice that #Metabase, the "AI" powered database vendor used by #Framework, has been hacked. And my data was part of the breach 😓
#AI is basically a swiss-cheese of easily exploitable security vulnerabilities. Shame on Framework for using them, and shame on me for trusting them with my data.
-
Oh, nice, @frameworkcomputer got pwn'd and all the customer info (name, email, address, phone number) got stolen. Via their BI provider Metabase.
As @Viss says, go the the cloud they said, it'll be great they said.
Wouldn't it be awesome if the companies getting breached suffered some sort of consequences for not securing their shit? I'm willing to bet that Metabase has a huge list of exploited-in-the-wild CVEs in their infra.
-
for security reasons you should change your name every 6 months
-
> Dear Valued #Framework Customer,
>
> We are writing to inform you of a data breach at our business intelligence database provider #Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.Process personal data in SaaS => high value target
-
🚨 Oh look, another #data breach! This time featuring #Metabase as the unwitting sidekick in the circus act of "Oops, Your Data is Showing!" 🎪 Framework's fans are just thrilled with the speedy notification—as if that's going to stitch their #privacy back together. 🤡🔧
https://community.frame.work/t/framework-data-breach-discussion/83939 #breach #Framework #notification #cybersecurity #HackerNews #ngated -
Framework discloses data breach via Metabase 0-day
https://community.frame.work/t/framework-data-breach-discussion/83939
Comments: https://news.ycombinator.com/item?id=49206130
#HackerNews #Framework #Metabase #data #breach #cybersecurity #vulnerability #0day
-
@frameworkcomputer sent me this email (they didn't post it on blog or fediverse):
Notice of Limited Data Breach
We confirmed that the following information was accessed:
Full name
Email address
Login IPs
Billing and shipping address information
Country
Address
City
State
Zip code
Phone number
Company
For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
Company
Phone
VAT
EIN
Billing Email
No other personally identifiable information, order information, or payment information was accessed.
Dear Valued Framework Customer,
We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.
We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.
We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.
What happened?
On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:
On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
Rotate the credentials for every database connected to your instance; and
Review the admin accounts on your instance and remove anything you don't recognize.
We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].
(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
This report is based on our own application logs. We did not query or read the data in your connected databases.
Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.
We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.
Sameer Al-Sakran Founder and CEO Metabase
We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker.
1/2
#framework #breach #hack #metabase -
Looks like #Metabase was breached via SQL injection from an unauthenticated endpoint. I was informed because #Framework emailed me saying my data was in the database that was accessed. Framework states they were notified of the #breach August 6th.
Metabase info: https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
What was accessed according to Framework:
We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:
Full name
Email address
Login IPs
Billing and shipping address information
Country
Address
City
State
Zip code
Phone number
CompanyFor Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
Company
Phone
VAT
EIN
Billing EmailIn the notification to Framework on the 6th, Metabase stated that it was a preliminary update and they were still investigating at that time, though they say they have patched the vulnerability.
-
Looks like #framework had a breach regarding their database provider #Metabase. I’ve never even bought anything with them. I had a reservation before but I cancelled it.
-
7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase
This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase. ...
Continued 👉 #openjdk #letsencrypt #installguide #jre #debian #reverseproxy #vps #selfhosting #selfhosted #proxyserver
7 Steps to Easily Configure Op... -
7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase
This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
What is OpenLiteSpeed?
OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you ...
Continued 👉 https://blog.radwebhosting.com/configure-openlitespeed-as-a-reverse-proxy-for-metabase/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #selfhosted #openjdk #reverseproxy #jre #selfhosting #proxyserver #vps #debian #letsencrypt #installguide -
7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase
This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
What is OpenLiteSpeed?
OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you ...
Continued 👉 https://blog.radwebhosting.com/configure-openlitespeed-as-a-reverse-proxy-for-metabase/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #installguide #selfhosted #vps #reverseproxy #proxyserver #debian #openjdk #jre #selfhosting #letsencrypt -
7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase
This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase. ...
Continued 👉 #selfhosted #installguide #jre #selfhosting #letsencrypt #debian #vps #openjdk #reverseproxy #proxyserver
7 Steps to Easily Configure Op... -
7 Steps to Easily Configure #OpenLiteSpeed as a Reverse #Proxy for #Metabase
This article provides a guide to configure OpenLiteSpeed as a reverse proxy for Metabase.
What is OpenLiteSpeed?
OpenLiteSpeed Web Server is great for building and deploying web applications. The WebAdmin Console enables you to quickly configure features that allow you ...
Continued 👉 https://blog.radwebhosting.com/configure-openlitespeed-as-a-reverse-proxy-for-metabase/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #openjdk #letsencrypt #reverseproxy #installguide #selfhosting #selfhosted #jre #proxyserver #vps #debian -
🚀 mb-cli v0.3.0 is out — a CLI for exploring your Metabase instance.
Highlights:
🗂️ New `collection` commands to browse collections, cards & dashboards
🔍 `card params` / `dashboard params list` to discover parameters before running
⏱️ `--timeout` flag + clean Ctrl+C cancellation
🔑 `MB_SESSION_TOKEN` auth — no admin API key required
📦 `go install` works out of the box
📖 New recipes cookbook