# Security incident involving an internal analytics system

> An unauthorised party exploited CVE-2026-72898 in a Metabase instance used for internal reporting. Payments, card data, funds and credentials were unaffected.
- **Author**: Ayush Agarwal
- **Published**: 2026-08-17
- **Category**: Security, Compliance
- **URL**: https://dodopayments.com/blogs/security-incident-internal-analytics-system

---

**Summary:** An unauthorised party exploited a vulnerability in a third-party reporting tool (Metabase) to gain access to one of our internal business analytics systems. Payment processing, card data, merchant funds, account credentials and API keys were not affected, and our PCI DSS certification is unaffected. No service was disrupted or degraded at any time. We became aware of the incident on 16 August 2026 and contained it within hours. We will keep updating this page as our review progresses.

The affected system is a self-hosted deployment of Metabase, a third-party open-source tool that we use for internal reporting only. It is separate from the systems that process payments.

The vulnerability exploited was CVE-2026-72898, a flaw in Metabase that allowed the software's authentication to be bypassed. Organisations running affected Metabase versions should apply the vendor's patched release immediately or, where immediate patching is not possible, restrict network access to the Metabase instance until the update can be applied.

We want to be transparent with you and keep you fully informed about what happened, what was and was not affected, and what we have done and are doing about it.

## What happened

An unauthorised third party gained access to this analytics system (Metabase) by exploiting CVE-2026-72898, an SQL injection vulnerability in Metabase that is the subject of the vendor's security advisory (GHSA-vwf4-m7j8-wcjf). The flaw allowed the software's authentication to be bypassed. Exploiting it did not require any Dodo Payments credential. No password, credential or multi-factor authentication factor was compromised.

We became aware of the incident on 16 August 2026. We immediately started our incident response process, and within hours, we contained the access, revoked every session, token and key associated with the affected system, and closed the vulnerability by upgrading to a patched release. A detailed technical investigation is ongoing and is being given full priority.

The unauthorised access was limited to this single internal reporting system and to a short, clearly bounded period. During that period, the third party viewed and queried reporting datasets available to that system. We have found no evidence of unauthorised access to any other Dodo Payments system.

## What was not affected

- **Payment processing was not affected.** Our payment authorisation, transaction processing and settlement systems were not accessed.
- **Full card numbers were not involved, and our PCI DSS certification is not affected.** The affected system does not hold full payment card numbers. Card processing is performed by our payment service providers, and cardholder data does not reside in the affected environment. Our PCI DSS certification is completely unaffected.
- **Your API keys and account credentials were not affected.** Merchant API keys, dashboard passwords and account credentials are not stored in the affected system and were not accessed.
- **No service was disrupted.** All Dodo Payments services, including payments, payouts, dashboard, and APIs, remained fully available throughout. There was no downtime or degradation at any time.
- **No funds were accessed.** No merchant funds were accessed or put at risk.
- **No destructive software was involved.** Nothing was altered or destroyed.

## What was affected

Our review has identified that information relating to some of our merchants was involved. We are determining the specific data categories involved and the merchants and individuals affected. We will contact any affected merchants directly at the earliest, and will update this page as our review concludes.

## What we have done

Immediately upon becoming aware of the unauthorised access, we moved to close the vulnerability and shut off every route back into the system:

- Upgraded the affected system to a patched release of the software.
- Restricted the vulnerable endpoint.
- Revoked all active sessions on the affected system.
- Revoked all OAuth access and refresh tokens associated with the affected system.
- Removed and rotated all internal API keys on the affected system, including any created by the unauthorised third party.
- Preserved forensic evidence to support the ongoing investigation.
- Identified and documented the infrastructure used by the unauthorised third party, to assist the authorities.

## What we are doing

Beyond fixing this specific issue, we are strengthening the surrounding architecture so that a vulnerability in any single internal tool cannot have this effect again:

- Removing direct internet exposure from our internal analytics infrastructure.
- Enforcing single sign-on, IP allow-listing and web application firewall protection across all internal administrative interfaces.
- Implementing a formal vulnerability-monitoring process for all self-hosted third-party software, with strict timelines for applying critical security patches.
- Expanding authentication-event logging and extending log retention across the affected environment.
- Re-architecting how internal reporting tools connect to underlying data stores, removing standing broad access.
- Engaging independent, certified security assessors to review and validate our remediation.

## What we need you to do

No action is required on your part at this time; if that changes for your account, we will contact you directly. In the meantime, we recommend the following precautions as a matter of good security practice:

- **Rotate your Dodo Payments API keys and passwords if you wish.** Your credentials were not affected by this incident, but periodic rotation is good security hygiene.
- **Be alert to phishing.** Dodo Payments will never ask for your password, API keys or OTPs by email or phone. Official communication about this incident will come only from an @dodopayments.com email address.

Growing companies are increasingly visible targets, and new vulnerabilities in widely used software are now exploited within days (sometimes hours) of being disclosed. AI is accelerating both sides: teams build and adopt software faster than they can inventory and patch it, while attackers use the same tools to weaponise disclosed flaws at machine speed. The practical defence is speed and visibility: know what you run, and patch critical vulnerabilities as soon as fixes are released.

If your business self-hosts Metabase, please ensure you are running a patched version that addresses CVE-2026-72898, and consider whether it needs to be reachable from the internet at all.

## Our commitment

We know that merchants trust Dodo Payments with their business and their data, and that this trust has to be earned continuously. We are sorry that this incident occurred. We hold ourselves to a higher standard than the law and industry practice require. We are committed to a full and thorough review of what occurred and are examining our systems end to end. Where we find weaknesses, we will fix them.

Independent validation of our security programme was already underway before this incident: our SOC 2 examination and our ISO/IEC 27001 certification are both in progress. Together with the measures described above, they are designed to ensure that an issue in any single third-party tool cannot again reach the data we hold. We are fully committed to protecting the information entrusted to us.

If you have any questions about this incident, or wish to confirm whether your data was involved, please contact us at privacy@dodopayments.com.
---
- [More Security articles](https://dodopayments.com/blogs/category/security)
- [All articles](https://dodopayments.com/blogs)