← Back to Articles Hub

Metabase Security Incident Update: What n8n Users Need to Know

By Alex • Published on August 19, 2026

Metabase Security Incident Update: What n8n Users Need to Know

Overview of the Breach

On 6 August 2026, n8n discovered an unauthorized intrusion into its Metabase analytics environment—a third‑party tool used internally for data reporting. The breach originated from a vulnerability that Metabase patched on 3 August 2026, the same day the malicious activity took place. While the incident was swiftly contained, a forensic investigation revealed that a total of 136 records were accessed across both n8n Cloud and self‑hosted users.

What Data Was Compromised?

The investigation broke down the compromised records into three distinct groups:

Another set of 62 records contained no personally identifiable information and pose no risk. Importantly, self‑hosted passwords are never stored with n8n, and only a historical bug had briefly stored a small number of n8n Cloud passwords in plain text—a bug that has already been fixed.

Immediate Response and Remediation

Following the discovery, n8n took several decisive actions:

  1. Metabase patched the vulnerability and terminated the compromised sessions.
  2. All potentially affected credentials were rotated, and audit logs were reviewed.
  3. n8n notified its Data Protection Officer, the Berlin Commissioner for Data Protection, and impacted users via direct email.
  4. The historical plain‑text password bug was rectified, and the 25 affected Cloud account holders were individually contacted.

What Users Should Do

If you received a personalized email from the n8n security team, follow the instructions within that message and reset your password immediately. Even if you were not directly contacted, you may still choose to reset your n8n Cloud password as a precaution. The password reset can be performed at any time via the help‑desk article linked in the original notice.

Looking Ahead

n8n emphasizes its commitment to security and transparency. While the breach exposed a relatively small amount of data, the incident highlights the importance of regular security audits, prompt patching, and clear communication with users.

Further Resources

For a complete timeline and additional guidance, refer to the official blog post: Metabase Security Incident Update. If you have any questions, you can reach the security team at help@n8n.io.