2026 Dodo Payments — Metabase CVE-2026-72898; internal analytics accessed; merchant reporting data involved
Data compromised
Company: reporting datasets in isolated Metabase instance; merchant-related information under review — not full card numbers, API keys, dashboard passwords, or payment-processing systems per notice. DireWolf leak-site listing Aug 15 (unverified scope).
Technical writeup
Verified company notice — August 16–20, 2026. Dodo Payments (global merchant-of-record / payments platform) detected unauthorised access on August 16, 2026 to a self-hosted Metabase deployment used only for internal business analytics, separate from payment authorisation, settlement, and cardholder data environments. Co-founders published on LinkedIn August 17; the company blog (updated August 20) states attackers exploited CVE-2026-72898 (critical Metabase SQL injection / authentication bypass, GHSA-vwf4-m7j8-wcjf) without any Dodo Payments credential, contained access within hours, upgraded Metabase, revoked sessions/tokens/keys, and preserved forensic evidence. Dodo says payment processing, merchant funds, full card numbers, API keys, dashboard passwords, and PCI DSS Level 1 posture were not affected and no services were disrupted. The notice acknowledges information relating to some merchants was involved via reporting datasets viewed/queried during a short bounded window; affected merchants will be contacted directly and [email protected] is offered for inquiries — no nationwide census at indexing. Ransomware.live indexed a DireWolf leak-site listing for DodoPayments discovered August 15, 2026 (financial-software sector); the company had not confirmed ransomware encryption or a public data dump at indexing and characterised impact as limited to the Metabase reporting system. recordsAffected 0 pending merchant/individual notice counts; companyConfirmed true.
Root cause
Unauthorised party exploited CVE-2026-72898 (Metabase unauthenticated SQLi / auth bypass) in self-hosted internal Metabase used for business analytics; detected Aug 16, 2026
References
- https://dodopayments.com/blogs/security-incident-internal-analytics-system
- https://www.ransomware.live/id/RG9kb1BheW1lbnRzQGRpcmV3b2xm
- https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
- https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/