Summary
- Environment: Metabase Cloud analytics instance
- Operational impact: Cypress reported test execution was unaffected
- Financial impact: No incident cost established in the reviewed evidence
- Record status: Developing record. Reviewed October 7, 2026; updated as evidence emerges.
What happened
Impact
Timeline
Threat Group & Attack Vector
Cypress attributed access to a previously unknown Metabase vulnerability. [2]
Metabase described SQL injection that created administrative sessions. [1]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
