{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ametabasemetabaseenterprise/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*","cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2023-38646"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Metabase"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Metabase"],"content_html":"\u003cp\u003eCVE-2023-38646 is a critical vulnerability affecting multiple versions of Metabase (prior to 0.43.7.2, 1.43.7.2, 0.44.7.1, 1.44.7.1, 0.45.4.1, 1.45.4.1, 0.46.6.1, and 1.46.6.1). This vulnerability exists within the setup validation process, specifically in the \u003ccode\u003e/api/setup/validate\u003c/code\u003e endpoint. An unauthenticated attacker can supply a specially crafted JSON payload that includes a malicious H2 database connection string. Due to improper input validation and handling of the \u003ccode\u003esubname\u003c/code\u003e parameter, the application is forced to execute system-level commands through the H2 database engine's driver functionality. The recent publication of multiple functional proof-of-concept exploits significantly lowers the barrier for exploitation, making immediate remediation essential for any internet-exposed Metabase instance.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing Metabase server.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted POST request to the \u003ccode\u003e/api/setup/validate\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes a JSON body with a \u003ccode\u003edetails\u003c/code\u003e object containing a malicious \u003ccode\u003esubname\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esubname\u003c/code\u003e parameter is configured to use the \u003ccode\u003eorg.h2.Driver\u003c/code\u003e class with a path containing a malicious SQL \u003ccode\u003eCREATE TRIGGER\u003c/code\u003e statement.\u003c/li\u003e\n\u003cli\u003eThe Metabase application processes the payload, triggering the H2 database driver to initialize the malicious connection string.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eCREATE TRIGGER\u003c/code\u003e statement executes on the backend, invoking Java's \u003ccode\u003eRuntime.getRuntime().exec()\u003c/code\u003e method.\u003c/li\u003e\n\u003cli\u003eThe attacker-specified shell command (e.g., base64 encoded bash command) executes on the underlying operating system.\u003c/li\u003e\n\u003cli\u003eSuccessful execution leads to full application or host compromise, potentially allowing for persistent access or further exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2023-38646 grants an attacker full remote code execution privileges with the context of the Metabase application. This exposes the organization to complete data exfiltration, service disruption, and potential lateral movement into the internal network where the database instance is hosted. With a CVSS score of 9.8, the impact includes full loss of confidentiality, integrity, and availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade Metabase to the latest patched version (\u0026gt;= 0.43.7.2, 1.43.7.2, 0.44.7.1, 1.44.7.1, 0.45.4.1, 1.45.4.1, 0.46.6.1, or 1.46.6.1).\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for unauthorized POST requests to \u003ccode\u003e/api/setup/validate\u003c/code\u003e containing strings indicative of H2 driver initialization or SQL trigger keywords (e.g., \u003ccode\u003eCREATE TRIGGER\u003c/code\u003e, \u003ccode\u003eorg.h2.Driver\u003c/code\u003e, \u003ccode\u003eRUNSCRIPT\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Metabase management interface, ensuring it is not accessible from the public internet.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect exploitation attempts at the webserver level.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T09:03:48Z","date_published":"2026-08-26T09:03:48Z","id":"https://feed.craftedsignal.io/briefs/2026-08-metabase-rce/","summary":"A critical pre-authentication Remote Code Execution vulnerability in Metabase allows unauthenticated attackers to execute arbitrary system commands via malicious H2 database connection strings.","title":"Critical Pre-Authentication RCE in Metabase (CVE-2023-38646)","url":"https://feed.craftedsignal.io/briefs/2026-08-metabase-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*","version":"https://jsonfeed.org/version/1.1"}