Metabase security incident update
Blog post from n8n
n8n disclosed a security incident involving Metabase, its internally used third-party analytics platform, in which an unauthorized party accessed and queried data on 3 August 2026 through a vulnerability that Metabase has since patched. The investigation found that 136 records containing user names and email addresses may have been accessed, including five records with bcrypt-hashed passwords for n8n Cloud accounts; because the queries returned variable results, n8n cannot identify the specific affected records. The company also identified a previously fixed historical issue that had stored a small number of n8n Cloud passwords in plain text and directly notified all 25 potentially affected account holders as a precaution. Metabase revoked relevant credentials and sessions, while n8n reviewed logs, rotated potentially affected credentials, addressed the historical bug, and notified relevant data-protection authorities. Users who received direct notification are advised to reset their passwords promptly, while other n8n Cloud users may reset theirs as an additional precaution.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.