Metabase A.I CyberSecurity Scoring
Metabase
Company Information
Website:http://www.metabase.com
Employees number:126
Number of followers:27,525
NAICS:518
Industry Type:Data Infrastructure and Analytics
Homepage:metabase.com
Metabase Risk Score (AI oriented)
Between 0 and 549
MetabaseData Infrastructure and Analytics
Updated:
17/09/2026
17/09/2026
532/1000
Critical
C
Metabase Global Score (TPRM)
xxxx
MetabaseData Infrastructure and Analytics
Score locked

MetabaseCritical
Current Score
532C (CRITICAL)
01000
8 incidents
-49.17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
598
Breach
09 Sep 2026 • Metabase
Metabase and Thankyou Payroll: New Zealand payroll firm apologises after being caught up in data breach
New Zealand Payroll Firm Hit by Data Breach Exposing Sensitive Customer Information
531
CRITICAL-67
THAMET1789079827
New Zealand Payroll Firm Hit by Data Breach Exposing Sensitive Customer Information
A New Zealand-based payroll provider, Thankyou Payroll, has confirmed a data breach affecting its customers after a third-party reporting tool was compromised. The incident, described as part of a "global" security incident, resulted in unauthorized access to sensitive customer data.
The breach occurred through Metabase, a third-party reporting tool used by Thankyou Payroll, which was taken offline following the discovery. While the company stated its own systems remained secure, the exposed data included names, IRD (tax) numbers, email and physical addresses, bank account details, and payment histories.
Thankyou Payroll, which serves multiple charities, disclosed the breach on Thursday, though the exact timeline of the unauthorized access remains unclear. The incident highlights the risks of third-party vulnerabilities in handling sensitive financial and personal information.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2026
603
Vulnerability
08 Sep 2026 • Metabase
Metabase, Framework and City Relay: London property manager breach may have exposed bank details and lockbox codes
City Relay Data Breach Exposes Customer Financial and Property Access Information
531
CRITICAL-72
THEMETCIT1789662413
City Relay Data Breach Exposes Customer Financial and Property Access Information
London-based property management firm City Relay has disclosed a data breach in which attackers accessed its Metabase Cloud instance twice, potentially extracting sensitive customer information. The incident, discovered on September 8, was reported to affected landlords and former users on September 14.
The compromised data includes names, email and physical addresses, phone numbers, financial details (bank account numbers, sort codes, IBANs, SWIFT references), property access codes, and account passwords. Attackers may have also obtained information on key storage locations and lockbox codes, raising concerns about physical security risks.
Dray Agha, Senior Manager of Security Operations at Huntress, noted that the exposure of readable passwords and financial data suggests inadequate encryption practices. He emphasized that sensitive information should be encrypted or tokenized to mitigate risks when third-party tools like Metabase are compromised.
City Relay stated that it has updated all exposed access codes and found no evidence of unauthorized property access or data misuse. However, the company advised customers to monitor bank accounts for fraudulent activity and remain vigilant against phishing attempts.
The breach’s full scope remains under investigation, with cybersecurity specialists and authorities involved. While City Relay manages thousands of properties across London and Paris, it has not disclosed the number of affected customers.
The attack may be linked to a zero-day SQL injection vulnerability in Metabase, disclosed on August 6, which impacted fewer than 3% of its customers before fixes were deployed. Other known victims include Framework and n8n, though Metabase has not confirmed whether the City Relay incident was part of the same campaign.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2026
610
Vulnerability
06 Sep 2026 • Metabase
Metabase and Mathspace: Breached! Tutoring platform Mathspace says 1m-plus Aussies implicated by data breach
Mathspace Data Breach Exposes Over 1 Million Users in Australia and New Zealand
603
CRITICAL-7
METMAT1788740628
Mathspace Data Breach Exposes Over 1 Million Users in Australia and New Zealand
Australian edtech platform Mathspace has disclosed a data breach affecting more than 1.07 million students, parents, teachers, and staff across Australia and New Zealand. The incident, confirmed on September 3, 2026, stemmed from an unpatched vulnerability in the company’s self-hosted Metabase reporting system.
The breach occurred after an attacker exploited a known flaw in Metabase, disclosed on August 6, 2026, which Mathspace failed to address due to an internal oversight in its vulnerability notification process. Unauthorized access began as early as August 10, with data exfiltrated on August 27, before the company detected the intrusion on September 3.
Exposed data included names, email addresses, user IDs, usernames, account creation dates, last login timestamps, and email verification statuses though passwords, SSO tokens, and authentication credentials remained secure. No academic or learning data was compromised. Mathspace has since taken its platform offline to remediate the issue and has notified regulators, including Australia’s OAIC and ACSC, as well as New Zealand’s Privacy Commissioner and NCSC.
The company is conducting a post-incident review to improve its vulnerability management and response processes. Notifications to affected individuals began on September 6, with no threat actor yet claiming responsibility.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
674
Breach
07 Aug 2026 • Metabase
Framework: Framework Laptops Hit by Data Breach Exposing All Customers
Framework Laptop Maker Discloses Major Data Breach Affecting All Customers
607
CRITICAL-67
FRA1786127124
Framework Laptop Maker Discloses Major Data Breach Affecting All Customers
Framework, the San Francisco-based modular laptop company known for its right-to-repair philosophy, has confirmed a data breach exposing the personal information of its entire customer base. The incident, disclosed this week via notifications to affected users, compromised names, email addresses, phone numbers, and physical shipping addresses effectively a full directory of every individual who has purchased one of the company’s devices.
The breach strikes a particularly damaging blow to Framework, which has built its brand on transparency and user trust. While the company states that no payment or financial data was accessed since credit card details were not stored in the compromised system the exposed information remains highly valuable to cybercriminals. Such data is commonly exploited for phishing attacks, SIM swapping, and identity theft.
Details about the breach remain limited. Framework has not specified when the unauthorized access occurred or how long attackers had access to customer data, leaving security experts questioning the company’s handling of the incident. The lack of clarity stands in contrast to Framework’s reputation for openness, further complicating its response.
The timing of the breach adds to the fallout, as the company has positioned itself as a disruptor in the tech industry, challenging traditional manufacturers with its repairable, user-friendly designs. The incident underscores the risks even transparency-focused companies face in safeguarding customer data.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
751
Breach
03 Aug 2026 • Metabase
Framework and Metabase: Framework customer information was accessed as part of a data breach
Framework Customer Data Exposed in Metabase Breach
674
CRITICAL-77
METFRA1786131154
Framework Customer Data Exposed in Metabase Breach
Framework, the manufacturer of repairable and upgradeable laptops, has disclosed a data breach affecting all its customers. In an email sent on August 6, the company revealed that customer names, login IP addresses, physical addresses, phone numbers, and email addresses were accessed during a cyberattack on Metabase, its business database provider. Payment information was not compromised.
The breach occurred after an attacker exploited an unknown zero-day vulnerability in Metabase’s systems, which the provider detected on August 3. Metabase has since patched the flaw and is conducting a forensic investigation with a third-party firm to assess the full scope of the incident. The company’s findings remain preliminary.
Framework confirmed it rotated credentials following the breach and found no evidence of unauthorized admin access or compromise beyond Metabase’s systems. The company is now reviewing its data storage practices with external vendors to prevent future incidents.
The breach adds to Framework’s recent challenges, including supply chain disruptions and rising component costs. Earlier this year, the company raised prices twice due to memory shortages and was forced to reduce RAM in some preorders for its Framework Laptop Pro, offering full refunds to affected customers.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Vulnerability
03 Aug 2026 • Metabase
Metabase: Second-hand ticket marketplace Tixel confirms customer information stolen in data breach
Tixel Customers Affected by Data Breach via Third-Party Analytics Provider
674
CRITICAL-77
MET1787984684
Tixel Customers Affected by Data Breach via Third-Party Analytics Provider
A data breach at Melbourne-based second-hand ticket marketplace Tixel has exposed customers’ email addresses and mobile numbers after an unauthorized party accessed a third-party analytics provider, Metabase.
Tixel notified users via email on Friday night, confirming that while sensitive data including passwords, credit card details, payment information, and purchase history remained secure, affected individuals should monitor for spam and phishing attempts. The company emphasized it would never request passwords or payment details via email or text.
The breach originated from a zero-day vulnerability in Metabase’s cloud services, exploited on August 3. Metabase revealed in a blog post that the attack likely leveraged AI-driven tools, specifically a Large Language Model (LLM), to execute a complex, multi-layered intrusion. The company stated that only under 3% of its customers were impacted and has since released a security update to fortify its systems.
Both Tixel and Metabase have been contacted for additional details.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Vulnerability
03 Aug 2026 • Metabase
Metabase: Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access
Critical Zero-Day Exploit in Metabase Grants Attackers Full Admin Access
674
CRITICAL-77
MET1786299845
Critical Zero-Day Exploit in Metabase Grants Attackers Full Admin Access
Metabase, a popular open-source business intelligence and data visualization platform, has confirmed active exploitation of a critical zero-day vulnerability (GHSA-vwf4-m7j8-wcjf) allowing unauthenticated attackers to gain full administrator control of affected instances. The flaw, rated with a maximum CVSS score of 10.0, impacts all versions from 0.58 through 0.63.
The vulnerability is an unauthenticated SQL injection in the publicly accessible POST /api/session/reset_password endpoint. Attackers can inject arbitrary SQL commands into Metabase’s database, manipulate records, and escalate privileges to an admin account. From there, they can extract stored credentials, access connected databases, and exfiltrate sensitive data.
Metabase first detected the exploit on August 3, when its own cloud platform was breached. The company patched the flaw within hours, automatically securing all Metabase Cloud customers. However, self-hosted deployments remain vulnerable until administrators apply the fix.
At least two companies Framework and Tally have reported data breaches linked to this zero-day, with unauthorized access to customer information, including names, addresses, phone numbers, and emails.
Security teams can detect exploitation by checking logs for a specific pattern: a POST /api/session/reset_password request returning a 400 status code, followed by a GET /api/user/current request returning 200. This sequence indicates successful session hijacking, and affected instances should be considered compromised.
Metabase has released patched versions (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5) for self-hosted deployments. Organizations running older versions (pre-0.58) are unaffected. If the vulnerable endpoint was exposed, security teams should revoke active sessions, audit API keys, review admin accounts, rotate database credentials, and inspect logs for unauthorized activity.
Given Metabase’s role as a central data hub, this flaw poses severe risks, potentially enabling broader breaches across connected systems. Self-hosted users are urged to patch immediately.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
751
JUNE 2026
750
MAY 2026
750
APRIL 2026
755
Vulnerability
27 Apr 2026 • Metabase
Metabase: PoC Exploit Released for Critical Metabase Enterprise RCE Vulnerability
Critical RCE Vulnerability in Metabase Enterprise Exploited in the Wild
750
CRITICAL-5
MET1777286018
Critical RCE Vulnerability in Metabase Enterprise Exploited in the Wild
Security researchers have disclosed a severe remote code execution (RCE) vulnerability in Metabase Enterprise, tracked as CVE-2026-33725, after a proof-of-concept (PoC) exploit was publicly released. The flaw, stemming from an H2 JDBC INIT injection weakness during serialization imports, allows unauthenticated attackers to execute arbitrary code or access sensitive files on vulnerable systems.
The vulnerability affects multiple Metabase Enterprise versions, including:
- 1.47.0–1.54.21
- 1.55.0–1.55.21
- 1.56.0–1.56.21
- 1.57.0–1.57.15
- 1.58.0–1.58.9
- 1.59.0–1.59.3
A Python-based PoC exploit, published by Hakai Security researcher Diego Tellaroli, automates the attack chain, increasing the risk of widespread exploitation. While the tool includes an educational disclaimer, its availability lowers the barrier for threat actors to launch automated attacks against exposed instances.
Metabase has released patched versions (1.59.4, 1.58.10, 1.57.16) to mitigate the flaw. Organizations unable to patch immediately are advised to restrict access to the Metabase admin interface, limit network exposure, and monitor logs for suspicious activity. Unpatched systems risk full compromise, data breaches, and potential lateral movement within enterprise networks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
755
FEBRUARY 2026
755
JANUARY 2026
755
DECEMBER 2025
755
NOVEMBER 2025
755
OCTOBER 2025
755
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Metabase ??
What was Metabase's A.I Rankiteo Cyber Score in August 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in July 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in June 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in May 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in April 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in March 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in February 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in January 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in December 2025 ??
What was Metabase's A.I Rankiteo Cyber Score in November 2025 ??
What was Metabase's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Metabase's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Metabase ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Metabase's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?