KEVIntel
9.8
CVSS
Critical

CVE-2023-38646

PUBLISHED

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the...

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
Metabase
Product
Metabase
Published
Jul 21, 2023
EPSS

Description

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2025-04-22 00:00:00 UTC · Source

Proof of concept available

Recorded 2023-07-30 09:56:52 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Apr 28, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

metabase_setup_token_rce

metasploit · Created Unknown

Metasploit module for CVE-2023-38646

DaniTheHack3r/CVE-2023-38646

github · Created 2024-03-04 23:01:43 UTC · 0 stars

CVE-2023-38646 Metabase 0.46.6 exploit

Mrunalkaran/CVE-2023-38646

github · Created 2023-11-07 03:57:15 UTC · 0 stars

Metabase Pre-Auth RCE POC

junnythemarksman/CVE-2023-38646

github · Created 2023-10-26 10:37:23 UTC · 0 stars

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

Red4mber/CVE-2023-38646

github · Created 2023-10-25 17:10:53 UTC · 2 stars

Python script to exploit CVE-2023-38646 Metabase Pre-Auth RCE via SQL injection

AnvithLobo/CVE-2023-38646

github · Created 2023-10-20 15:21:08 UTC · 0 stars

RCE Exploit for CVE-2023-38646

Pyr0sec/CVE-2023-38646

github · Created 2023-10-15 01:29:37 UTC · 8 stars

Exploit script for Pre-Auth RCE in Metabase (CVE-2023-38646)

passwa11/CVE-2023-38646

github · Created 2023-10-12 02:24:12 UTC · 0 stars

nickswink/CVE-2023-38646

github · Created 2023-10-11 20:17:14 UTC · 3 stars

CVE-2023-38646 Unauthenticated RCE vulnerability in Metabase

yxl2001/CVE-2023-38646

github · Created 2023-10-08 07:36:57 UTC · 0 stars

kh4sh3i/CVE-2023-38646

github · Created 2023-08-19 11:47:08 UTC · 8 stars

Metabase Pre-auth RCE (CVE-2023-38646)

robotmikhro/CVE-2023-38646

github · Created 2023-08-09 14:05:24 UTC · 27 stars

Automatic Tools For Metabase Exploit Known As CVE-2023-38646

fidjiw/CVE-2023-38646-POC

github · Created 2023-08-03 08:06:10 UTC · 1 stars

CVE-2023-38646-POC

shamo0/CVE-2023-38646-PoC

github · Created 2023-08-02 13:21:58 UTC · 12 stars

Metabase Pre-auth RCE

Zenmovie/CVE-2023-38646

github · Created 2023-07-31 11:18:21 UTC · 1 stars

Proof of Concept for CVE-2023-38646

securezeron/CVE-2023-38646

github · Created 2023-07-30 09:56:52 UTC · 20 stars

POC for CVE-2023-38646

Xuxfff/CVE-2023-38646-Poc

github · Created 2023-07-30 09:33:28 UTC · 2 stars

Chocapikk/CVE-2023-38646

github · Created 2023-07-30 01:12:24 UTC · 3 stars

Remote Code Execution on Metabase CVE-2023-38646

0xrobiul/CVE-2023-38646

github · Created 2023-07-29 13:07:00 UTC · 15 stars

Metabase Pre-auth RCE (CVE-2023-38646)!!

Pumpkin-Garden/POC_Metabase_CVE-2023-38646

github · Created 2023-07-28 11:43:06 UTC · 6 stars

For educational purposes only

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Detected by Nuclei

  • Added to KEVIntel

  • Detected by Metasploit