ANSSI, the French national cybersecurity agency, has confirmed that 118 accounts of its innovation lab were compromised through a critical zero-day in Metabase, a self-hosted dashboard tool; the interministerial digital directorate (DINUM) was hit too. A judicial investigation is open. The lesson: dashboards and internal tools exposed to the internet.
What happened
In early August 2026 the open-source analytics tool Metabase warned that a previously unknown flaw, rated 10 out of 10, was being exploited: a chain of weaknesses around password reset let an attacker create a valid session and, from there, gain administrator access to self-hosted instances. A fix shipped within days.
ANSSI has now confirmed, in the first report of its REACTIV operation, that it was among the victims: 118 Metabase accounts of its innovation lab, including about thirty external users, were compromised — usage statistics, usernames, email addresses and hashed passwords, according to the reports. According to 01net, the interministerial digital directorate (DINUM) was hit through the same flaw. The Paris prosecutor has opened an investigation. ANSSI’s director described the attack as “not the attack of the century” but illustrative: it targeted a widely deployed tool that is “little monitored because it looks harmless”.
Why this concerns you
Dashboards, BI tools, monitoring consoles, wikis and CI servers are often installed by a team for a project, opened to the internet for convenience, and then forgotten. They hold credentials to your databases and are rarely patched. Exploitation started the very day the flaw was published.
What to do now
- Inventory your internal web tools — Metabase, Grafana, Kibana, Jenkins, phpMyAdmin, wikis — and check which are reachable from the internet.
- Put them behind a VPN or an authenticating proxy with multi-factor authentication; none of them needs to be public.
- Patch them like production: subscribe to their security advisories and include them in your update cycle. If you run Metabase, make sure you are on a version released after the August fix.
- Clean up accounts: reset passwords after any incident, disable unused accounts (ANSSI disabled those inactive for three months), and give the tool read-only database credentials.
Our take
If the agency in charge of France’s cyber defence can be caught by a forgotten dashboard, any company can. The most exposed systems are rarely the main website — they are the small tools nobody remembers installing.
Sources
- ZDNet — Piratage de comptes de l’Anssi : « pas l’attaque du siècle » mais une illustration de la menace
- 01net — Fuite de données à l’ANSSI : une enquête est ouverte
- Le Monde Informatique — ANSSI : le gendarme de la cybersécurité français piraté
Worried your servers are exposed? Our team audits, patches and monitors Linux and cloud infrastructure 24/7.
Talk to an expert