# Security incident involving an internal analytics system

DevFeed: [Security incident involving an internal analytics system](<https://devfeed.tech/articles/security-incident-involving-an-internal-analytics-system-10343.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/security-incident-internal-analytics-system/>)

Author: Ayush Agarwal

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [datasets](<https://devfeed.tech/topics/datasets.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [analytics](<https://devfeed.tech/tags/analytics.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [datasets](<https://devfeed.tech/tags/datasets.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Dodo Payments discloses unauthorized access to a self-hosted Metabase analytics system after exploitation of CVE-2026-72898, an SQL injection flaw that bypassed authentication. The company says payment processing, card data, merchant funds, credentials, API keys, and other systems were not affected. Access was contained within hours on 16 August 2026, sessions and keys were revoked, and the vulnerability was closed by upgrading Metabase.

## Source excerpt

An unauthorised party exploited CVE-2026-72898 in a Metabase instance used for internal reporting. Payments, card data, funds and credentials were unaffected.