Critical severity9.8NVD Advisory· Published Jul 21, 2023· Updated Jun 17, 2026
CVE-2023-38646
CVE-2023-38646
Description
Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*range: <0.43.7.2
- cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*range: <1.43.7.2
- (no CPE)range: <0.46.6.1, <1.46.6.1, 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, 1.43.7.2
- Metabase/Metabase open sourcedescription
- osv-coords3 versionspkg:apk/chainguard/metabasepkg:apk/chainguard/metabase-compatpkg:apk/chainguard/metabase-oci-entrypoint
< 0+ 2 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
6- www.metabase.com/blog/security-advisorynvdVendor Advisory
- github.com/metabase/metabase/issues/32552nvdIssue Tracking
- github.com/metabase/metabase/releases/tag/v0.46.6.1nvdRelease Notes
- news.ycombinator.com/itemnvdIssue Tracking
- packetstormsecurity.com/files/174091/Metabase-Remote-Code-Execution.htmlnvd
- packetstormsecurity.com/files/177138/Metabase-0.46.6-Remote-Code-Execution.htmlnvd
News mentions
1- Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationThe Hacker News · Aug 8, 2026