Metabase Flaw Exposes Data at ANSSI and DINUM
118 accounts compromised in ANSSI's innovation lab, two instances hacked at DINUM: the national cybersecurity agency appears in its own state data breach report. The cause is a critical flaw in Metabase. Here's what we know.
As a reminder, the Prime Minister asked ANSSI on September 1, 2026 to launch Operation REACTIV, for "REsponse & ACTion Interministerielle face aux Violations de données". I also published an article about this initiative that allows ANSSI to impose emergency measures on ministries after data breaches. On September 30, 2026, the French agency published the first status update on Operation REACTIV. It reports that 99 data breaches had been reported since August 1, 2026, 67 of which have been confirmed.
This document comes the day after ANSSI's incident report on the cyberattacks that targeted the DGFiP (see my article on the DGFiP cyberattack). But this time, ANSSI is also being transparent about its own issues. Its innovation lab was itself hit by a data breach, and there is also one to report on the DINUM side (Interministerial Digital Directorate).
ANSSI and DINUM: what was compromised
The common denominator between these two incidents has a name: Metabase, an open source data visualization platform used to build dashboards. A popular tool you probably know. Reading this report reveals the following:
- ANSSI innovation lab: exploitation of a Metabase vulnerability led to the compromise of 118 Metabase user accounts, including around 30 external accounts. The data involved includes usage statistics, usernames, email addresses, and password hashes. Following this intrusion, ANSSI updated the vulnerable instances, reset all account passwords, and disabled accounts unused for more than three months.
- DINUM: two Metabase instances associated with ProConnect and Nuage-Public were compromised. The exfiltrated data includes administrative information about public organizations (SIREN, SIRET, budgets, headcount), contribution metadata for open source projects, and anonymized login histories.
On the DINUM side, the report aims to be reassuring about the nature of the stolen information: "This data is already public", it says. Indeed, it is worth pointing that out given the nature of the data.
We also need to put the incident in perspective. This concerns the accounts of a Metabase platform used by ANSSI's innovation lab, not the agency's information system as a whole. Nothing in the document suggests a broader intrusion.
Metabase, the recurring entry point
The vulnerability in question, tracked as CVE-2026-72898, is an authentication-free SQL injection. It allows access to the Metabase application database and can grant administrator rights on the instance. This critical security flaw was fixed by Metabase in a patch released on August 6, 2026, and was also the subject of an alert from CERT-FR on September 10, 2026.
Something catches my attention: the security flaw was fixed on August 6, 2026. The CERT-FR alert bulletin is dated September 10, 2026, which is one month later. What if this alert bulletin was published following the intrusion on ANSSI and DINUM instances? That is just a hypothesis, but it could provide a clue about the timing of this intrusion. "CERT-FR is aware of numerous compromises of vulnerable Metabase instances.", the report states.
For its part, ANSSI says in its report that it observed massive exploitation of this flaw since early August 2026. It lists nine compromised instances within ministries, including:
- France VAE: the portal was compromised via the Metabase vulnerability on August 8, 2026, just two days after the patch was released. The attacker gained privileged access and exfiltrated all user data.
- Qualicharge: 102,000 charging sessions and around 100 technical accounts were exfiltrated from the application used to manage electric vehicle charging infrastructure.
- Zéro Logement Vacant: the entry point appears to have been a Metabase instance, in a breach affecting 48 million property owners.
If you are hosting a Metabase instance and it has not been updated in a while, now is the time to do it. Otherwise, Metabase recommends blocking public access to the /api/session/reset_password path.


