Advisory
Published 2026-10-08
Verified 2026-10-09

JPCERT/CC warns of a wave of personal data leaks at Japanese organisations through abused mobile-app APIs, exposed BI and admin systems and the Metabase SQL injection CVE-2026-72898; Macnica counts 119 web-system leaks this year

JPCERT/CC issued alert JPCERT-AT-2026-0030 on 8 October 2026 about a run of unauthorised-access incidents that leaked large amounts of personal data from Japanese organisations around September 2026. It names no attacker or victim and calls its picture limited and fragmentary. It describes three patterns: attackers pulling API keys from smartphone apps and calling APIs in ways that look like normal use, then hunting for APIs that return too much data, have excessive privileges, expose member functions to anonymous users or mishandle sessions (weak admin passwords and known flaws were also seen); attackers scanning each target for a range of known flaws and stealing configuration and backup files; and exploitation of CVE-2026-72898, the unauthenticated Metabase SQL injection (CVSS 10.0) that was a zero-day against Metabase's own cloud in August and is on CISA's KEV list. Targets include consumer apps, business intelligence tools and staff-facing management systems their operators never meant to be public. The alert lists eight source IP addresses, five User-Agent strings and API controls such as access checks on every endpoint, public or not. The security research centre of Macnica, cited by the alert, counted 119 publicly reported web-system personal data leaks in Japan this year to 6 October (84 in all of 2025, 62 in 2024), 81 of them since July. Primary: JPCERT/CC (Japanese); wire: The Hacker News.

Product
Web and mobile-app APIs, business intelligence tools and admin systems; Metabase (CVE-2026-72898)
Versions
Metabase: upgrade to at least Metabase's current minimum safe release for your version line (list updated 14 Aug 2026)
CVSS
10.0 (Metabase CVE-2026-72898); other cases are misconfiguration and API logic flaws, no CVSS
Exploited in Australia?
unknown
Patch to
Upgrade Metabase to its minimum safe release or later (or block /api/session/reset_password until you can). Check that every API endpoint enforces authorisation, rotate keys embedded in mobile apps, take BI and admin consoles off the public internet, and search logs for the IP addresses and User-Agents in the JPCERT/CC alert.

Primary: JPCERT/CC — JPCERT-AT-2026-0030: alert on recent successive unauthorised access at domestic organisations (8 Oct 2026, Japanese) · Vendor: JPCERT/CC — Metabase SQL injection CVE-2026-72898 alert (14 Aug 2026, Japanese) · CVE: CVE-2026-72898 · The Hacker News — Japan sees sharp rise in web data leaks amid mobile API abuse and Metabase attacks (8 Oct 2026)

breaches cloud identity