Home / Companies / Checkly / Blog / Post Details
Content Deep Dive

Metabase Security Incident

Blog post from Checkly

Post Details
Company
Date Published
Author
-
Word Count
1,069
Company Posts That Month
1
Language
English
Hacker News Points
2
Post removed?
No
Summary

On 3 August 2026, an attacker exploited a zero-day vulnerability in Checkly’s Metabase Cloud analytics instance to obtain an administrator session and read data from a separate warehouse containing copies of operational and account data for approximately 26 minutes. Checkly states that its production platform, production database, check execution infrastructure, alerting systems, user accounts, and service or user API keys were not breached or modified, while Metabase patched the vulnerability and blocked the attack. Potentially exposed information included credentials or sensitive values entered directly into check configurations, such as custom headers, cookies, query parameters, authorization values, scripts, and per-check environment variables, along with cryptographic hashes of OpenTelemetry API keys; Checkly Secrets, locked variables, and per-check secrets were exposed only in encrypted form, while global secret values and alert-channel credentials were not exposed. Customers are advised to rotate directly configured credentials and OTEL API keys, review protected systems for suspicious activity since the incident date, and reauthorize relevant integrations. Checkly has rotated affected internal credentials, reset Metabase access, audited accounts and cloud logs, contacted affected customers, and plans to reduce sensitive-data exposure in analytics systems, improve sanitization and access controls, and strengthen vendor-security alerting and customer communications.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 9 2,244 480 132 -13%
OpenTelemetry 6 757 153 55 -30%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.