← Incident database

leanbody-metabase-2026 · Disclosed 2026-09-15

LEAN BODY: unauthorized access and impact

A Metabase vulnerability was exploited; the operator considers missed necessary updates a likely contributing factor. Theft affected about 440,000 accounts, including former users; this is not a unique-person count.

Known vulnerability

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    A Metabase vulnerability was exploited.

    [s1]§§1-4,8(ブラウザで本文確認)
  • Reported fact

    Theft affected about 440,000 accounts, including former users; this is not a unique-person count.

    [s1]§§1-4,8(ブラウザで本文確認)
  • Assessment

    The company assesses omitted necessary updates as a likely contributing factor.

    [s1]§§1-4,8(ブラウザで本文確認)

Timeline

  1. Event date reported by the source. [s1]

  2. Disclosure date established by the reviewed notice. [s1]

Reported response

  • Reported fact

    The tool was updated, the route blocked, sessions and rogue accounts and keys revoked, and DB privileges minimized.

    [s1]§§1-4,8(ブラウザで本文確認)

Evidence relevant to prevention

Patch information / update review

The update omission is a company assessment. Review deployed versions and update history; the CVE and pre-attack fix date are undisclosed.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The reviewed disclosures do not establish attacker use of AI.

An omitted Metabase update is reported as a likely contributor, not a proven complete entry chain. Version, CVE and prior patch timing are undisclosed.

Sources

  1. [s1] LEAN BODY · Primary source

    LEAN BODY:事故に関する公表資料 ↗

    Reviewed 2026-10-09