Your internal dashboards were never meant to be public — JPCERT says attackers are finding them anyway

By George Bailey   Published: 10/09/26   4 min read

The dashboards and admin panels your staff use every day were never meant for the public. Japan’s national CERT says that’s exactly where a wave of recent data leaks came from. On October 8, JPCERT/CC warned that BI tools and employee-only admin systems, built on the assumption that “nobody outside will ever hit this,” are being found and drained.

The advice isn’t specific to Japan. If you run Metabase, an internal API behind a mobile app, or an admin page someone exposed “temporarily,” it applies to you.

“Internal only” is a promise to yourself. It isn’t a firewall rule.

What happened

JPCERT/CC alert JPCERT-AT-2026-0030 says personal data leaks from unauthorized access at Japanese organizations have been piling up around September 2026. It describes three patterns:

Why it matters

These systems sit close to the data. A BI tool usually holds stored credentials for your warehouse. An admin API can change who is allowed to see what. And because they’re “internal,” they often get the weakest authentication and the slowest patching.

What to do first

Forward this

For whoever owns our dashboards and internal apps: Japan’s CERT warned on October 8 that internal BI tools and admin systems are being found online and drained of data. Can we confirm which of ours are reachable from the internet, and that any Metabase instance is on the patched release?

Details

Hunt / verify

Slack paste: JPCERT (Oct 8): wave of data leaks via internet-exposed BI tools/admin systems: scanning for known bugs, internal-API abuse (role changes, rogue accounts, NoSQLi, stolen keys), Metabase CVE-2026-72898. Action: inventory exposed dashboards/APIs, put them behind VPN/SSO, Metabase to 0.58.24/0.59.21/0.60.17/0.61.11/0.62.9/0.63.5, rate-limit + per-route access control.

Sources

George Bailey

George Bailey is the byline of the CyberExperts editorial desk, the team behind the CyberExperts Daily Brief. The desk covers vulnerabilities, breaches and security news from vendor advisories, CISA alerts and other primary sources, and links those sources in every story. Questions or corrections: [email protected].