Attackers reached an internal Metabase deployment
Dodo Payments said attackers exploited CVE-2026-72898 against a self-hosted Metabase system used for internal reporting. The company contained the access and said its investigation remained in progress.
- Observed impact
- Dodo said it would contact every affected merchant directly. Its public update did not quantify the merchants or reporting data involved.
- Reported boundary
- Dodo reported no disruption, funds movement, payment or cardholder data exposure, or exposure of passwords, API keys, webhook secrets, card numbers, or stored payment tokens.
- Current status
- Contained; investigation ongoing
Watch for direct notice from Dodo and treat unexpected requests for credentials or one-time codes as phishing.