Mark RadarMARK RADAR
About
EN
Sign in

Metabase Zero-Day Attacks Expose Customer Data at Framework, Tally and Kilo Code

1 reports · First detected 2026-08-11 · Last active 2026-08-11

Metabase is an open-source business intelligence platform widely used to connect corporate databases and build analytics dashboards. The exploitation of CVE-2026-72898 as a zero-day is significant because compromised deployments can give attackers unauthorized access to data centralized for reporting, turning a trusted analytics tool into an entry point for breaches across technology companies and online services.

Recent attacks affected laptop maker Framework, online form platform Tally and AI coding assistant provider Kilo Code. Investigations found that exposed records primarily contained customer names and email addresses. As of Aug. 11, 2026, there was no indication that payment information had been compromised, while the affected companies continued reviewing the scope of unauthorized access and the data held in their Metabase instances.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)