Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.
https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html
https://thehackernews.com/2026/04/over-1000-exposed-comfyui-instances.html
https://www.vulncheck.com/blog/return-of-the-kinsing
https://thehackernews.com/2025/07/hackers-exploit-apache-http-server-flaw.html
https://github.com/nuclide-research/metabase-cve-2023-38646
https://github.com/jonathan-corbin/htb-cve-pocs
https://github.com/jonathan-corbin/cve-arsenal
https://github.com/1392081456/sigma-detection-rules
https://github.com/BreezeGalaxy/CVE-2023-38646
https://github.com/cyberwithcyril/VulhubPenTestingReport
https://github.com/XiaomingX/cve-2023-38646-poc
https://github.com/Red4mber/CVE-2023-38646
https://github.com/AnvithLobo/CVE-2023-38646
https://github.com/nickswink/CVE-2023-38646
https://github.com/SUT0L/CVE-2023-38646
https://github.com/Boogipop/MetabaseRceTools
https://github.com/alexandre-pecorilla/CVE-2023-38646
https://github.com/joaoviictorti/CVE-2023-38646
https://github.com/thatformat/Hvv2023
https://github.com/GREENHAT7/Hvv2023
https://github.com/fidjiw/CVE-2023-38646-POC
https://github.com/raytheon0x21/CVE-2023-38646
https://github.com/lazysec0x21/CVE-2023-38646
https://github.com/LazyySec/CVE-2023-38646
https://github.com/hheeyywweellccoommee/CVE-2023-38646-glwax
https://github.com/Chocapikk/CVE-2023-38646
https://github.com/0xrobiul/CVE-2023-38646
https://github.com/Loginsoft-Research/Linux-Exploit-Detection
https://www.metabase.com/blog/security-advisory
https://news.ycombinator.com/item?id=36812256
https://github.com/metabase/metabase/releases/tag/v0.46.6.1
https://github.com/metabase/metabase/issues/32552
http://packetstormsecurity.com/files/177138/Metabase-0.46.6-Remote-Code-Execution.html
http://packetstormsecurity.com/files/174091/Metabase-Remote-Code-Execution.html