August 11, 2026
- Metabase's unauthenticated SQL injection zero-day is spreading downstream, and there's still no CVE. The maximum-severity
reset_passwordflaw grants remote administrator access to the analytics platform, and its blast radius now reaches hosted customers of Metabase itself (Dark Reading). LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after suspicious server activity at a third-party vendor (BleepingComputer), and Framework confirmed customer data loss and rotated credentials (The Register). A loopback-only Docker lab comparing patched vs. vulnerable builds is public (earlier coverage). (discussion) · Vulnerabilities & Exploits
in Metabase Zero-Day Blast Radius Widens to LexisNexis and Framework