leanbody-metabase-2026 · Disclosed 2026-09-15
LEAN BODY: unauthorized access and impact
A Metabase vulnerability was exploited; the operator considers missed necessary updates a likely contributing factor. Theft affected about 440,000 accounts, including former users; this is not a unique-person count.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
A Metabase vulnerability was exploited.
[s1]§§1-4,8(ブラウザで本文確認) - Reported fact
Theft affected about 440,000 accounts, including former users; this is not a unique-person count.
[s1]§§1-4,8(ブラウザで本文確認) - Assessment
The company assesses omitted necessary updates as a likely contributing factor.
[s1]§§1-4,8(ブラウザで本文確認)
Timeline
Reported response
- Reported fact
The tool was updated, the route blocked, sessions and rogue accounts and keys revoked, and DB privileges minimized.
[s1]§§1-4,8(ブラウザで本文確認)
Evidence relevant to prevention
Patch information / update review
The update omission is a company assessment. Review deployed versions and update history; the CVE and pre-attack fix date are undisclosed.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The reviewed disclosures do not establish attacker use of AI.
An omitted Metabase update is reported as a likely contributor, not a proven complete entry chain. Version, CVE and prior patch timing are undisclosed.
Sources
[s1] LEAN BODY · Primary source
LEAN BODY:事故に関する公表資料 ↗Reviewed 2026-10-09