Surprisingly Useful AI Article Enhancements
Melbourne-based ticket resale platform, Tixel, has notified users that their email addresses and mobile numbers may have been accessed after an attacker exploited a zero-day vulnerability in its third-party analytics provider, Metabase.
Tixel told affected users that the incident occurred inside Metabase’s systems, not within the Tixel platform itself.
“Our website and account systems were not breached,” the company stated in a notification sent to users.
No passwords, credit card details, payment information or purchase history were involved in the incident, according to the company.
Part of a wider Metabase breach
The Tixel disclosure is the latest in a growing list of companies affected by a critical SQL injection vulnerability in Metabase that was exploited as a zero-day, impacting versions 1.58 and above.
The vulnerability, tracked as CVE-2026-72898, carries a CVSS severity score of 10.0 – the highest possible rating. It affects the password-reset functionality and can be reached through the publicly accessible POST /api/session/reset_password endpoint, allowing a remote attacker to inject SQL into the Metabase application database without authenticating.
Metabase CEO, Sameer Al-Sakran, warned in a blog post that the company’s cloud platform had been compromised through the previously unknown flaw.
Metabase confirmed that attackers were actively exploiting the vulnerability against real-world environments.
Metabase is an open-source business intelligence and data visualisation tool that customers can connect to databases including Databricks, MongoDB, Oracle, Snowflake, Amazon and BigQuery, among others, to access analytics, query and visualise data, and build dashboards.
What was accessed
In its notification to users, Tixel indicated that the breach was limited in scope.
“Our investigation with Metabase indicates your email address and mobile number may have been accessed as part of this incident,” the company stated.
Tixel confirmed that user accounts, including any tickets or listings, were unaffected.
The company warned users to watch for phishing and spam as a result of the exposure.
“Be cautious of any unexpected message about your tickets, orders or account,” Tixel advised. “If a message feels off, don’t click anything in it – go straight to tixel.com or contact us.”
Tixel also reminded users that it would never ask for passwords or payment details by email or text, and would never direct payments outside tixel.com.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
Remediation steps
Tixel stated that it changed the keys connecting its systems to Metabase, checked for any further access – finding none – and strengthened its security and data-handling practices.
On Metabase’s side, the company blocked the endpoints used for the attack, then identified and patched the vulnerability. Metabase Cloud customers had their instances upgraded and patched automatically.
Metabase has also engaged an independent forensic firm and notified relevant authorities and regulators, according to Tixel’s notification.
The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalogue, requiring federal agencies to apply fixes by 14 August 2026.
Other companies affected
Tixel is not alone in disclosing a breach stemming from the Metabase vulnerability.
Several companies have already confirmed they were affected, including Kilo Code, Tally, Framework, n8n and ChecklyHQ, with stolen data including usernames, emails, API keys and Slack tokens across various incidents.
Laptop manufacturer, Framework, disclosed that attackers accessed names, email addresses, phone numbers, physical addresses and login IP addresses through its compromised Metabase cloud instance, though payment information and order records were not affected.
Workflow automation platform, n8n, confirmed that 136 records containing names and email addresses were accessed across its user base.
Scale of exposure
Roughly 2,500 Metabase instances are estimated to be internet-exposed, and about 25 per cent of self-hosted cloud deployments are fully accessible online.
Dataminr’s threat research team conducted a broad exposure assessment on 8 August, with approximately 11,000 hosts observed as probable self-hosted Metabase deployments.
Tixel directed users with further questions to privacy@tixel.com and pointed to the Australian Cyber Security Centre at cyber.gov.au and the ACCC’s Scamwatch at scamwatch.gov.au for general online safety guidance.
About Tixel
Tixel is a Melbourne-based ticket resale marketplace founded in 2017. The platform operates as a fan-to-fan marketplace for buying and selling tickets to concerts, festivals and events, with AI-powered fraud detection and price caps that prevent scalping.
Unlike some resale platforms, Tixel caps resale prices at 110 per cent of face value, verifies tickets before transfer and works with event organisers to provide a secondary market.
Last Updated on August 30, 2026 by Nick Ross



