← iMapper

2026 iMapper — 0xSec Metabase claim; 2,463 accounts + password hashes (unverified)

2026 2.5K records affected Share on X

Data compromised

Actor-claimed account table: usernames, emails, password hashes, roles, phones, Stripe IDs, MFA flags (unverified)

Technical writeup

Unverified leak claim: Cyberattaque.org reported 0xSec claimed exploitation of Metabase CVE-2026-72898 (CVSS 10) against French building-measurement vendor iMapper, publishing ~2,463 account rows with password hashes and related fields, and asserting ability to access other tables. iMapper had not confirmed at indexing. recordsAffected 2463; companyConfirmed false.

Root cause

Unverified 0xSec claim of Metabase CVE-2026-72898 exploitation against iMapper (Aug 2026)

References