Automation

n8n Discloses Security Incident Affecting Analytics Tool and a Small Number of User Accounts

n8n disclosed a security incident involving unauthorized access to its internal Metabase analytics environment, affecting 136 records with names and email addresses, including five bcrypt-hashed passwords. The company notified German authorities and affected users, and recommends password resets as a precaution.

Neura News

Neura News

Neura Market Editorial

August 8, 20263 min read
n8n Discloses Security Incident Affecting Analytics Tool and a Small Number of User Accounts

Workflow automation provider n8n has disclosed a security incident involving unauthorized access to its internal Metabase analytics environment, affecting a small number of user accounts. The company said it became aware of the incident on 6 August 2026, after unauthorized activity occurred three days earlier, on 3 August 2026.

What Happened

n8n uses Metabase, a third-party open-source analytics tool, internally. An unauthorized third party accessed and queried certain data available through that environment. Metabase has since patched the vulnerability that allowed the unauthorized activity.

n8n began an investigation with Metabase and its own security, legal, and data teams. The investigation confirmed that 136 records containing names and email addresses were accessed across all n8n users, including both self-hosted and n8n Cloud customers. Of those 136 records, five contained bcrypt-hashed passwords of n8n Cloud accounts.

The company noted that self-hosted passwords are never shared with n8n. The queries used in the incident returned a variable, non-deterministic set of rows each time they ran, so n8n cannot determine which specific records were accessed.

Historical Bug and Plain-Text Passwords

n8n also addressed a historical bug, previously fixed, that caused a small number of n8n Cloud account passwords to be stored in plain text. The company considers it unlikely that plain-text passwords were accessed during this incident. As a precaution, n8n contacted all 25 account holders affected by that historical bug.

The company said it reviewed its own audit logs after being notified, rotated potentially affected credentials, and rectified any users affected by the historical bug. Metabase terminated the relevant sessions and revoked the credentials used in the incident.

Notification and Response

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

n8n notified its Data Protection Officer and the Berlin Commissioner for Data Protection and Freedom of Information, the German data protection authority. The company also advised users who received a direct email about the incident to follow the instructions and reset their password. Users not directly contacted may still reset their n8n Cloud password as an additional precaution.

Password reset instructions are available via a helpdesk article, and questions can be directed to help@n8n.io. The n8n team apologized for the concern caused.

What Users Should Do

The company emphasized the limited scope of the incident. Only 136 records were accessed, five contained hashed passwords, and 25 accounts were tied to the historical plain-text bug. Self-hosted users were not affected in terms of password exposure, since their passwords are never shared with n8n.

n8n urged anyone who received a direct notification to act promptly. For others, resetting a cloud password remains an optional precaution. The company said it has taken steps to secure its environment and prevent further unauthorized access.

Ongoing Investigation

n8n continues to work with Metabase and its internal teams. The investigation confirmed the unauthorized access and the scope of data involved. The company has not disclosed whether any further action is planned, but it has rotated credentials and notified the relevant authorities.

The incident highlights the risks of third-party analytics tools, even when used internally. n8n said it has reviewed its audit logs and taken corrective measures. The company has not indicated that any other systems were affected.

Related on Neura Market

More from Neura News

AI Models

42 Mathematicians Urge Royal Society to Warn Government and Media About AI Existential Risk

Forty-two mathematical fellows, including Fields Medal winners Martin Hairer, Peter Scholze, and Wendelin Werner, have signed an open letter urging the Royal Society to warn the UK government and media about existential risks from advanced AI. The letter follows recent breakthroughs in which leading models solved open research problems, including a Millennium Problem. None of the signatories are affiliated with AI companies. The group warns that AI labs' estimates of existential risk above ten percent must not be dismissed as hype, and that by the time the situation becomes obvious to the public, it may be too late to act.

Sep 18·2 min read
Developer

Steve Yegge Shuts Down Gas Town After Failing to Build Anything Else With It

Steve Yegge shut down Gas Town, his ultra-vibed coding agent orchestrator, after admitting he never built anything else with it despite heavy subscription spend. Databricks reported a 60% coding spend increase after rolling out GPT-6 Astra to 3,500 engineers, OpenAI published a misalignment disclosure framework with six case reports, and Xiaomi ran MiMo-V2.6 RL training in public with live telemetry.

Sep 18·21 min read