Security

Tally and n8n exposed logins through a Metabase zero-day

Published Aug 12, 20265 sources · 3 independent

A maximum-severity flaw in the dashboard tool your vendors use to read their own customer data let attackers walk out with account records.

If you have an n8n account or a Tally login, change that password now. Neither company was broken into. Metabase was — the business intelligence tool their teams used to query their own customer tables — and the records sitting in those dashboards went with it.

What happened

Metabase said on 6 August 2026 that an attacker had used a previously unknown flaw to reach Metabase Cloud. The bug needs no login: an unauthenticated attacker can inject arbitrary SQL through the password-reset endpoint and take administrator control of an instance. From there the stored credentials for every connected database are in reach. Versions 1.58 and above are affected; anything below 58 is not. The flaw is CVE-2026-72898, rated 10.0 — the maximum — and CISA added it to its Known Exploited Vulnerabilities catalogue on 11 August.

Who has confirmed exposure

n8n reported that 136 records containing names and email addresses were accessed, across both self-hosted and Cloud users, and that five of those also included bcrypt-hashed Cloud passwords. In the same notice it disclosed a separate historical bug that had left 25 Cloud passwords stored in plain text. Tally told users that email addresses and password hashes were reached, and that forms and submitted answers were not. Framework lost names, email addresses, phone numbers, billing and shipping addresses and login IPs, but not payment details. Kilo Code, now part of Anaconda, reported names, emails and Slack access tokens, since invalidated.

What to do

  • Reset your n8n and Tally passwords, and every other account where you reused them. Turn on two-factor authentication while you are in there.
  • Expect phishing. An email address plus a confirmed vendor relationship is the raw material for a convincing fake support mail. Go to the vendor directly rather than clicking through.
  • If you self-host Metabase, patch today. The fixed releases are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5. Metabase Cloud instances were patched by the company and need no action.
  • If your instance was reachable from the internet, Metabase tells self-hosters to revoke active sessions, review API keys and admin accounts, rotate the credentials for connected databases and check access logs.

No amount of vendor due diligence would have caught this. You cannot audit the internal dashboard a supplier points at its own customer table. The part you control is password reuse.

Why it matters

Your credentials can leak from a product you have never bought, because it is what your vendor uses to look at its own customer table. Reset anything you reused across n8n, Tally and other accounts, and patch immediately if you self-host Metabase.

Reported by Software Crit from the sources above. Every story is confirmed against at least two independent publishers before publication.

Get the weekly roundup

Honest reviews, practical comparisons and the tool news that actually changes your stack.