Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence76%
Public exploitation · VTP factREPORTED
Assessment
Affected Metabase Open Source and Enterprise versions permit unauthenticated remote command execution at the server's privilege level. One supplied press source reports in-the-wild zero-day exploitation, but its independence is unknown and the CVE is not represented as KEV in this bundle.
Why it matters
The flaw is network-accessible, low complexity, and can fully compromise the Metabase server.
Commands inherit the server's privileges, potentially exposing connected data and application secrets.
EPSS 0.98677 is strong predictive context but does not independently validate exploitation.
Evidence
1 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
The exploitation and zero-day claims derive from one press evidence item with unknown independence.
Technical details are reported, but functional public exploit reliability is not established.
Deployment exposure and first-party activity are unknown.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Next watchpoint
Inventory Metabase versions against the supplied fixed releases.
AI baseline history (2)
BASELINE ASSESSED
Metabase unauthenticated command executiongpt-5.6-sol · high
BASELINE ASSESSED
Unauthenticated command execution in Metabasegpt-5.6-sol · high
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.99100th percentile · prediction
Evidence confidence64%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
EPSS is 0.99; this is predictive context, not exploitation evidence.
02
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
02
Material change ledger
What changed
No material changes are recorded for this subject.
03
Claim provenance
Evidence and source independence
1publications detected
1underlying evidence chains
0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.
06:5808 Aug
ZERO DAY
Zero Day
The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.
05
Original publications
Source record
The Hacker NewsPRESSUNKNOWN
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.