We were made aware on 6 August 2026 of a security incident affecting Metabase, a third-party analytics tool used internally by n8n. The unauthorised activity took place on 3 August 2026 - Metabase has since patched the vulnerability that allowed it.

We immediately began an investigation with Metabase and our security, legal, and data teams. Our investigation confirmed that an unauthorized third party accessed and queried certain data available through n8n’s Metabase environment.

We're publishing this update to explain what we found and the action we're recommending for a small number of affected accounts.

What information was involved

We have confirmed that 136 records containing names and email addresses were accessed across all of our users, both self-hosted and n8n Cloud. Five of these records contained bcrypt-hashed passwords of n8n Cloud accounts, self-hosted passwords are never shared with n8n. Because the queries used returned a variable, non-deterministic set of rows each time they are run, we cannot determine which specific records were accessed.

Our investigation also identified a historical bug, which was previously fixed, that caused a small number of n8n Cloud account passwords to be stored in plain text. Whilst we consider it unlikely that these records were accessed during this incident, we have contacted all 25 account holders directly as a precaution.

What we have done

Metabase has patched the vulnerability, terminated the relevant sessions, and revoked the credentials used in the incident. Since being notified, we have been reviewing our own audit logs; rotated potentially affected credentials; rectified any users affected by the historical bug; and notified our Data Protection Officer as well as the Berlin Commissioner for Data Protection and Freedom of Information.

What you should do

If you received a direct email from us about this incident, please follow the instructions in that email and reset your password as soon as possible.

If we have not directly contacted you about this, you may still choose to reset your n8n Cloud password as an additional precaution.

You can reset your password at any time on the page described in this helpdesk article.

Questions

If you have questions about this notice or your account, please contact help@n8n.io.

We take the security of your account seriously and are sorry for the concern this may cause.

The n8n team

Share with us

n8n users come from a wide range of backgrounds, experience levels, and interests. We have been looking to highlight different users and their projects in our blog posts. If you're working with n8n and would like to inspire the community, contact us 💌

SHARE