The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Metabase Zero-Day Exploited in Wild Grants Admin Access to Customer Data

Ingrid Solheim
2026-08-08
# Metabase Zero-Day Exploited in Wild Grants Admin Access to Customer Data There is a specific kind of horror reserved for the person whose job it is to manage the data warehouse. You spend months building dashboards, cleaning sets, and ensuring that only the right people can see the right columns. Then you find out that your business intelligence tool (the very thing meant to make sense of your data) has essentially become a front door with the lock removed. The Metabase zero-day is currently making its way through the wire. It's an unauthenticated remote access vulnerability that allows attackers to bypass the login screen entirely and land straight in the administrator's seat. Once you're an admin, you aren't just looking at a chart; you're querying the underlying database. The fallout is already hitting the news cycle. Framework has reported that all of its customers were affected after this flaw was exploited. This is where the paperwork becomes interesting. When a tool like Metabase is used by a service provider, the vulnerability doesn't just sit in one house; it spreads through every client they manage. For the compliance officers at those downstream firms, the clock has started. Depending on where their customers live, they now have a very tight window to figure out exactly what was exfiltrated before the regulators start asking why a BI tool had unauthenticated admin access in 2026. We often treat these tools as internal utilities, like a plumbing system that stays behind the walls. The mistake is assuming that because it's "internal," it doesn't need the same rigour as a public-facing API. In reality, a BI tool is the highest-value target in the building because it's already connected to everything. If you're wondering who has to file the notifications for the Framework breach, I suspect the legal teams are currently arguing over whether this counts as a "third-party vendor failure" or a "systemic security lapse." In Brussels, they generally don't care about the distinction; they just want to see the impact assessment on their desk within 72 hours. On a different scale of mismanagement, we have Unlimited Technology Systems. They've reported a breach affecting north of 3.8 million patients. Healthcare is currently sitting at #3 on the targeting table for the week, with 125 stories in seven days. It's a sector that consistently fails the basic test of data hygiene. When you're handling records for nearly 4 million people, you shouldn't be surprised when someone decides to walk through the door, but you should be surprised that the door was so easy to open. The real question here is what happened to the encryption. If the data was encrypted at rest and the keys were managed properly, a breach of this size would be a nuisance rather than a catastrophe. Instead, we're looking at millions of people whose personal health information is now likely being priced on a forum in Eastern Europe. I've seen enough of these filings to know that the "we take your privacy seriously" press release is usually written by someone who has never actually looked at the server logs. The paperwork for 3.8 million victims is staggering. Even if the notifications are automated, the sheer volume of individual queries and "did you get my data?" emails will choke their support desk for months. It's a logistical nightmare that most firms don't budget for until after the fine lands. Then we have the N-able situation. If you've been following the N-central drama, you know it's not just about the initial entry. The latest development involves attackers establishing persistence via Cloudflare Tunnels. N-able has issued Hotfix 2, but a patch is only useful if you can actually clear the intruder out of the house first. If an attacker has already set up a tunnel, they don't need the vulnerability to get back in; they have their own private road into the system that bypasses the front gate entirely. This turns a patching exercise into a forensic hunt. It reminds me of some of the older supply chain campaigns from five or six years ago, the ones where the vendor would release a patch, and the customers would apply it, thinking they were safe, while the attackers sat comfortably in a separate process that the patch didn't touch. The parallel holds perfectly here: we are still treating persistence as an after-thought rather than part of the primary recovery process. For those who enjoy the slow grind of the legal system, there is a bit of closure on the Snowflake front. An attacker has finally pleaded guilty to hacking 165 companies. It's a modest number compared to the millions of records stolen, but it represents a rare moment where the paperwork actually reaches a conclusion. Usually, these things vanish into the ether or get settled with a quiet payment and a non-disclosure agreement. The wire is heavy today: 54 data breach stories alone in the last few hours. It's a noisy environment, which is exactly how attackers like to operate. They hide their high-value strikes in the middle of a storm of low-level noise. I'm also keeping an eye on the developer ecosystem. Nearly 800 malicious npm packages were recently flagged for delivering RATs and infostealers. This is the kind of "death by a thousand cuts" that keeps security teams awake. You can't patch your way out of a situation where your developers are accidentally inviting attackers into the build pipeline because they wanted a convenient library for date formatting. The recurring theme this week is the failure of the "trusted middleman." Whether it's Metabase, N-able, or an npm package, we keep outsourcing our trust to tools that aren't built to hold it. We treat these vendors as black boxes; we assume they're secure because we pay them a monthly subscription fee. The uncomfortable question is: when does the liability shift? Currently, the vendor releases a patch and considers their job done. The customer takes the hit on the data loss and pays the fine. I suspect that until regulators start hitting the vendors, not just the victims, with the actual cost of these breaches, we'll keep seeing "unauthenticated admin access" as a feature of modern BI tools. I'll be watching the Framework notifications. If they try to claim the Metabase flaw was an "unforeseen edge case," I'll be checking the Oslo archives for similar excuses from ten years ago. They usually sound exactly the same.
◼
← More from the Desk Live Wire →

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.