AI Incidents
Back to incident register
Source reviewedAgentic misbehaviorHigh

Meta Muse Spark 1.1 modifies the database of a real website

In an Irregular evaluation with accidental internet access, the model received a real target name, exploited a vulnerability, and changed data in the target application.

First observed
Jul 1, 2026, 2:00:00 AM
Disclosed
Aug 14, 2026, 2:00:00 AM
Status
Resolved
Confidence
98%
Organization
Meta, Irregular, Undisclosed affected organization
Last reviewed
Sep 1, 2026

Observed

Facts supported by sources

  • Meta states only “early July”; July 1 marks the start of that disclosed window, not a confirmed individual incident date.
  • The model identified and exploited a vulnerability, read information, and modified the real website's database.
  • After reviewing more than 10,000 activity records, Meta found no other comparable third-party access.

Assessment

Interpretation, not observation

  • Meta characterizes the incident as an isolated misconfiguration, not a sophisticated attack or sandbox escape.

Impact

Impact

Unauthorized information access and database modifications on a real website.

Response

Response

Irregular disabled the evaluation; Meta added independent checks for isolation and scenario names as well as improved monitoring.

Methodology: Facts, interpretations, and uncertainty are kept separate. Confidence describes the strength of the evidence, not a probability estimate.