
CVE-2026-XXXX: Metabase SQLi — Trezor Customer Data Exposed (June 2026)
CVE-2026-XXXX — Metabase SQL Injection
CVE-2026-XXXX is a high-severity zero-day SQL injection vulnerability in Metabase, actively exploited in June 2026 to compromise ShipMonk, a third-party logistics provider for Trezor. Attackers leveraged this flaw to access and exfiltrate personal data of nearly 14,000 Trezor customers. The CVSS score is pending, but exploitation is confirmed in the wild by the ShinyHunters extortion group.
Attack Vector
Attackers exploited an unauthenticated SQL injection in Metabase, enabling arbitrary database queries on ShipMonk’s infrastructure. The breach required Metabase to be internet-accessible and unpatched. The attackers, identified as ShinyHunters, used the vulnerability to enumerate and extract customer records, including names, addresses, emails, and phone numbers. No indicators of compromise (IOCs) have been published, but organizations should review Metabase logs for anomalous query patterns and unauthorized data access.
Who Is at Risk
Organizations running Metabase instances exposed to the internet are at immediate risk, especially if unpatched. ShipMonk, the affected logistics provider, suffered a breach impacting Trezor customers globally. Trezor’s core systems remain uncompromised, but any company using Metabase for customer or order management should assume exposure if vulnerable. Customers whose data was processed by ShipMonk between 2021 and 2026 are specifically impacted.
Patch & Mitigate
- Patch: Upgrade Metabase to the latest version released after June 2026 addressing CVE-2026-XXXX. Apply vendor hotfixes immediately.
- Workaround: Restrict Metabase access to trusted internal networks and disable public endpoints until patched.
- Detect: Audit Metabase and database logs for suspicious SQL queries, large data exports, or access from unfamiliar IP addresses since May 2026.
MITRE ATT&CK
- TA0006 — Credential Access: Attackers leveraged SQL injection to access sensitive customer data.
- TA0009 — Collection: Data was systematically exfiltrated from ShipMonk’s Metabase instance.
Source: https://www.securityweek.com/14000-trezor-customers-impacted-by-data-breach-at-shipmonk/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

