On August 6, 2026, we learned of a security incident affecting Metabase, a third-party analytics tool used internally by n8n. The unauthorized activity occurred on August 3, 2026, and Metabase has already patched the vulnerability that allowed it. We immediately launched an investigation with Metabase and our security, legal, and data teams, confirming access by an unauthorized party to certain data in n8n’s Metabase environment. This update explains what we found and the actions we recommend for a small number of affected accounts.
What happened, and when did it occur?
The unauthorized activity took place on August 3, 2026, and we were informed on August 6, 2026. Metabase has already fixed the vulnerability that enabled the activity. We engaged Metabase and our security, legal, and data teams immediately to investigate and confirm the scope of access.
From the first hours, we focused on establishing facts. Our priority was to understand which data was potentially accessible through n8n’s Metabase environment. We are publishing this update to describe verified findings and provide clear guidance to those potentially affected.
Metabase is a third-party analytics tool that we use internally. The incident occurred within that environment. The vulnerability enabling unauthorized activity has been remediated. Relevant sessions were terminated, and credentials used during the incident were revoked.
Our investigation confirms access by an unauthorized third party and queries run against certain data in n8n’s Metabase environment. Below, we provide verified details about data types, record counts, and our response steps so you know what to do next.
What information was involved?
We confirmed access to 136 records containing names and email addresses across all our users, both self-hosted and n8n Cloud. Five of these records contained bcrypt-hashed passwords of n8n Cloud accounts; self-hosted passwords are never shared with n8n. Because the queries returned a variable, non-deterministic set of rows each time, we cannot determine which specific records were accessed.
These figures reflect the confirmed scope of access within available logs and executed queries. They apply to users who self-host n8n and to n8n Cloud users. Our security team reports only verifiable facts and avoids assumptions where data cannot provide a definitive answer.
Our investigation also identified a historical bug, previously fixed, that caused a small number of n8n Cloud account passwords to be stored in plain text. We consider it unlikely that these records were accessed during this incident, but as a precaution, we directly contacted all 25 affected account holders.
Because of the non-deterministic nature of the queries, we cannot assemble a precise list of specific rows accessed. We therefore provide aggregate counts, describe field types, and offer guidance to those we contacted directly, as well as preventive steps for other n8n Cloud users.
“We have confirmed that 136 records containing names and email addresses were accessed across all of our users, both self-hosted and n8n Cloud. Five of these records contained bcrypt-hashed passwords of n8n Cloud accounts, self-hosted passwords are never shared with n8n.”
What have we done so far?
Metabase has patched the vulnerability, terminated relevant sessions, and revoked credentials used in the incident. Since being notified, we have been reviewing our own audit logs, rotating potentially affected credentials, rectifying any users impacted by the historical bug, and notifying our Data Protection Officer and the Berlin Commissioner for Data Protection and Freedom of Information.
We worked closely with Metabase to ensure the root vector was addressed and access halted. Containment steps included session termination and revoking credentials that may have been used during the incident. These actions are intended to minimize further risk.
Within our environment, we performed a thorough audit log review and promptly rotated potentially affected secrets. We also corrected the impact of the historical bug for the relevant n8n Cloud users it may have affected, bringing those accounts to a secure state.
We officially notified our Data Protection Officer and the Berlin Commissioner for Data Protection and Freedom of Information. This communication is part of our responsible approach and transparent reporting of confirmed facts and completed actions.
What should you do now?
If you received a direct email from us about this incident, please follow the instructions in that email and reset your password as soon as possible. If we have not contacted you directly, you may still choose to reset your n8n Cloud password as an additional precaution. You can reset your password at any time on the page described in the relevant helpdesk article.
We reached out directly to a small number of account holders we believe could be affected. For them, the best next step is an immediate password reset following the email instructions. This helps quickly reduce potential risk.
If you did not receive an email, the decision to reset your password remains yours as a preventive measure. We report only verified details and offer this step to those who want to act cautiously. It complements the measures we have already taken within our own infrastructure.
Remember that self-hosted passwords are never shared with n8n. Five records among the accessed data contained bcrypt-hashed n8n Cloud account passwords, and we have provided guidance to users we contacted directly. For others, we offer the preventive option of a password reset.
Questions and support
If you have questions about this notice or your account, please contact help@n8n.io. We take the security of your account seriously and are sorry for the concern this may cause. We publish this update to provide clear answers and understandable next steps.
Thank you for your attention to this notice. We are providing verified facts only: event dates, scope of access, our actions, and your recommended steps. If you received a direct notification, please follow the instructions and reset your password as soon as possible.
“We take the security of your account seriously and are sorry for the concern this may cause.”
Based on n8n Official Blog.