Workflow automation provider n8n has disclosed a security incident involving unauthorized access to its internal Metabase analytics environment, affecting a small number of user accounts. The company said it became aware of the incident on 6 August 2026, after unauthorized activity occurred three days earlier, on 3 August 2026.
What Happened
n8n uses Metabase, a third-party open-source analytics tool, internally. An unauthorized third party accessed and queried certain data available through that environment. Metabase has since patched the vulnerability that allowed the unauthorized activity.
n8n began an investigation with Metabase and its own security, legal, and data teams. The investigation confirmed that 136 records containing names and email addresses were accessed across all n8n users, including both self-hosted and n8n Cloud customers. Of those 136 records, five contained bcrypt-hashed passwords of n8n Cloud accounts.
The company noted that self-hosted passwords are never shared with n8n. The queries used in the incident returned a variable, non-deterministic set of rows each time they ran, so n8n cannot determine which specific records were accessed.
Historical Bug and Plain-Text Passwords
n8n also addressed a historical bug, previously fixed, that caused a small number of n8n Cloud account passwords to be stored in plain text. The company considers it unlikely that plain-text passwords were accessed during this incident. As a precaution, n8n contacted all 25 account holders affected by that historical bug.
The company said it reviewed its own audit logs after being notified, rotated potentially affected credentials, and rectified any users affected by the historical bug. Metabase terminated the relevant sessions and revoked the credentials used in the incident.
Notification and Response
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
n8n notified its Data Protection Officer and the Berlin Commissioner for Data Protection and Freedom of Information, the German data protection authority. The company also advised users who received a direct email about the incident to follow the instructions and reset their password. Users not directly contacted may still reset their n8n Cloud password as an additional precaution.
Password reset instructions are available via a helpdesk article, and questions can be directed to help@n8n.io. The n8n team apologized for the concern caused.
What Users Should Do
The company emphasized the limited scope of the incident. Only 136 records were accessed, five contained hashed passwords, and 25 accounts were tied to the historical plain-text bug. Self-hosted users were not affected in terms of password exposure, since their passwords are never shared with n8n.
n8n urged anyone who received a direct notification to act promptly. For others, resetting a cloud password remains an optional precaution. The company said it has taken steps to secure its environment and prevent further unauthorized access.
Ongoing Investigation
n8n continues to work with Metabase and its internal teams. The investigation confirmed the unauthorized access and the scope of data involved. The company has not disclosed whether any further action is planned, but it has rotated credentials and notified the relevant authorities.
The incident highlights the risks of third-party analytics tools, even when used internally. n8n said it has reviewed its audit logs and taken corrective measures. The company has not indicated that any other systems were affected.

