Metabase Security Incident Update: What n8n Users Need to Know
Overview of the Breach
On 6 August 2026, n8n discovered an unauthorized intrusion into its Metabase analytics environment—a third‑party tool used internally for data reporting. The breach originated from a vulnerability that Metabase patched on 3 August 2026, the same day the malicious activity took place. While the incident was swiftly contained, a forensic investigation revealed that a total of 136 records were accessed across both n8n Cloud and self‑hosted users.
What Data Was Compromised?
The investigation broke down the compromised records into three distinct groups:
- 7 records containing cloud usernames and email addresses.
- 5 records that included names, cloud usernames, email addresses, and
bcrypt-hashed n8n Cloud passwords. - 62 records with names and email addresses whose exact exposure could not be confirmed due to the non‑deterministic query pattern.
Another set of 62 records contained no personally identifiable information and pose no risk. Importantly, self‑hosted passwords are never stored with n8n, and only a historical bug had briefly stored a small number of n8n Cloud passwords in plain text—a bug that has already been fixed.
Immediate Response and Remediation
Following the discovery, n8n took several decisive actions:
- Metabase patched the vulnerability and terminated the compromised sessions.
- All potentially affected credentials were rotated, and audit logs were reviewed.
- n8n notified its Data Protection Officer, the Berlin Commissioner for Data Protection, and impacted users via direct email.
- The historical plain‑text password bug was rectified, and the 25 affected Cloud account holders were individually contacted.
What Users Should Do
If you received a personalized email from the n8n security team, follow the instructions within that message and reset your password immediately. Even if you were not directly contacted, you may still choose to reset your n8n Cloud password as a precaution. The password reset can be performed at any time via the help‑desk article linked in the original notice.
Looking Ahead
n8n emphasizes its commitment to security and transparency. While the breach exposed a relatively small amount of data, the incident highlights the importance of regular security audits, prompt patching, and clear communication with users.
Further Resources
For a complete timeline and additional guidance, refer to the official blog post: Metabase Security Incident Update. If you have any questions, you can reach the security team at help@n8n.io.