Vulnerability threat dossier

CVE-2023-38646

metabasemetabase

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

VTP deterministic threat36.2of 100 · CVSS excluded

VTP analyst assessment

Metabase unauthenticated command execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence76%
Public exploitation · VTP factREPORTED

Assessment

Affected Metabase Open Source and Enterprise versions permit unauthenticated remote command execution at the server's privilege level. One supplied press source reports in-the-wild zero-day exploitation, but its independence is unknown and the CVE is not represented as KEV in this bundle.

Why it matters

  • The flaw is network-accessible, low complexity, and can fully compromise the Metabase server.
  • Commands inherit the server's privileges, potentially exposing connected data and application secrets.
  • EPSS 0.98677 is strong predictive context but does not independently validate exploitation.

Evidence

1 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The exploitation and zero-day claims derive from one press evidence item with unknown independence.

Technical details are reported, but functional public exploit reliability is not established.

Deployment exposure and first-party activity are unknown.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Inventory Metabase versions against the supplied fixed releases.

AI baseline history (2)
  1. BASELINE ASSESSED
    Metabase unauthenticated command executiongpt-5.6-sol · high
  2. BASELINE ASSESSED
    Unauthenticated command execution in Metabasegpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.99100th percentile · prediction
Evidence confidence64%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.99; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:596ab81c2b7bd7bac499b413c11aec2aef15bc7eda9b3339f8d1f7ef4a4369dfACTIVE
Evidence
Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
64%claim confidence
UNKNOWNreport:596ab81c2b7bd7bac499b413c11aec2aef15bc7eda9b3339f8d1f7ef4a4369dfACTIVE
Evidence
04

Event history

Threat timeline

  1. 06:5808 Aug
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 06:5808 Aug
    ZERO DAY

    Zero Day

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

05

Original publications

Source record

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

CVE-2023-38646
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score36.2vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction19.74 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Unknown
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.