CVE-2023-38646Active Exploitation(metabase / metabase)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for metabase metabase systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

5.0/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • metabase

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-09-08)
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
metabase

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-04-05: 1Mentions · 2026-04-06: 1Mentions · 2026-06-14: 1Mentions · 2026-08-07: 1Mentions · 2026-08-11: 1Mentions · 2026-09-08: 2PoC Mentioned / Linked · 2026-04-06: 1PoC Mentioned / Linked · 2026-06-14: 1Active Exploitation · 2026-04-05: 1Active Exploitation · 2026-08-07: 1Active Exploitation · 2026-09-08: 2Technical Details · 2026-04-05: 1Technical Details · 2026-04-06: 1Technical Details · 2026-06-14: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-11: 1Technical Details · 2026-09-08: 104-0504-0606-1408-0708-1109-08
Signal classification3 categories
Active Exploitation
457.1%
Disclosure
228.6%
PoC
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-051
Active Exploitation1
2026-04-061
Disclosure1
2026-06-141
PoC1
2026-08-071
Active Exploitation1
2026-08-111
Disclosure1
2026-09-082
Active Exploitation2
Full discourse7 posts
  • Code2Shell@Code2Shell
    Active Exploitation

    🚨 CVE-2023-38646 -> Remote Code Execution A critical vulnerability in Apache HTTP Server allows attackers to execute arbitrary code remotely. This flaw could lead to full system compromise and is already being actively exploited. **How it works:** - **Exploitation via Malicious Request:** The flaw lies in how Apache HTTP Server processes certain HTTP/2 requests. By sending a specially crafted request, an attacker can trigger a buffer overflow. - **Buffer Overflow:** This overflow can overwrite critical memory, allowing attackers to control program execution and execute arbitrary commands. - **Default Configuration Vulnerable:** The exploit affects default configurations, making it widespread and easy to target. *Why critical?* It allows attackers to gain system-level access, facilitating lateral movement and data theft across networks. Follow @code2shell for more AppSec & Hacking content.

    Post summary

    The post reports that CVE-2023-38646 is a remote code execution vulnerability in Apache HTTP Server, exploiting a HTTP/2 buffer overflow, and is already being actively exploited in the wild.

    0001066
    3 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    ShinyHunters exploited CVE-2023-38646 to gain admin access to Mathspace's Metabase instance, maintaining persistence for 17 days before exfiltrating 1M+ student records. This campaign targeted multiple orgs' analytics platforms simultaneously. Runtime segmentation can help limit blast radius when BI tools are compromised. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/mathspace-data-breach-shinyhunters-metabase-2026

    Post summary

    ShinyHunters actively exploited CVE‑2023‑38646 to compromise Mathspace’s Metabase, achieving persistent admin access and exfiltrating over 1 million student records, indicating real‑world exploitation of the vulnerability.

    0000086
    2.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows ShinyHunters exploited CVE-2023-38646 to compromise ShipMonk's Metabase platform, then moved laterally to exfiltrate data on 81,000 Trezor customers. Runtime segmentation could have limited blast radius across connected systems. #SupplyChainSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/trezor-data-breach-impact-now-reaches-81000-customers

    Post summary

    ShinyHunters used CVE-2023-38646 to compromise ShipMonk’s Metabase platform, laterally move across the network, and exfiltrate data from 81,000 Trezor customers, demonstrating an active exploitation in the wild.

    0000098
    2.0K followersView on X
  • NewNormal Security@NewScanTeam
    Disclosure

    NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 11 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 💉 Unauthenticated SQL injection in a BI dashboard — SQL with no login at all, ending in an admin account (Metabase CVE-2026-72898, Metabase CVE-2026-72899) ⚡ Pre-auth RCE via a public setup token — reads the setup secret served to anonymous callers, then runs commands on the host (Metabase CVE-2023-38646) 🖥️ Analytics install that was never set up — whoever reaches it first claims the admin account, and every database credential added to it later (Metabase) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve&s=x #infosec #AppSec #SQLi #CSO #REDTEAM

    Post summary

    The post announces recent Metabase CVEs, detailing an unauthenticated SQL injection and a pre‑auth RCE, and promotes a new scanning tool without discussing PoCs, exploits, or patches.

    00000158
    5 followersView on X
  • Vixen Sorceress@sorceress_vixen
    Active Exploitation

    Framework 遭 Metabase 0day 攻击BI 工具成供应链攻击新面 开源 BI 工具 Metabase 未授权 RCE 漏洞(CVE-2023-38646),黑客批量扫描植入后门窃取数据、横向渗透 AI 时代供应链攻击:不攻击模型、攻击喂模型的数据管道/调度工具/BI/笔记本/向量库 属于守模型如防贼、守数据管道如防火、结果火从厨房起

    Post summary

    Metabase’s unauthenticated RCE flaw (CVE‑2023‑38646) is actively exploited, with attackers scanning, planting backdoors, exfiltrating data, and moving laterally in supply‑chain attacks.

    00000244
    775 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 #CVE‑2023‑38646, NoSQLi, SSRF & IDOR: Real‑World Multi‑Tenant Web Exploitation Chain – Hands‑On Lab Guide https://undercodetesting.com/cve-2023-38646-nosqli-ssrf-idor-real-world-multi-tenant-web-exploitation-chain-hands-on-lab-guide/ Educational Purposes!

    Post summary

    The tweet promotes a lab guide that demonstrates exploitation of CVE‑2023‑38646 through NoSQLi, SSRF, and IDOR for educational purposes.

    0000034
    607 followersView on X
  • Code2Shell@Code2Shell
    Disclosure

    🚨 CVE-2023-38646 -> Privilege Escalation A potential ticking time bomb in your network! CVE-2023-38646 is a vulnerability that allows attackers to escalate their privileges from an ordinary user to an administrator on vulnerable systems. 🔥 How it Works: - **Exploit Target**: Attackers exploit improper input validation within a system service. - **Privileged Action**: Manipulates system calls triggering unintended behaviors. - **Payload Injection**: Injects malicious code to gain elevated privileges and access restricted resources. - **Bypassing Controls**: Evades conventional security measures, posing significant access risks. 🌟 Why is it Critical? - *Wide Impact*: Affects multiple systems and potentially exposes critical infrastructure. - *Easy to Execute*: With publicly available proof-of-concept exploits, any skilled attacker can leverage it. - *Critical Assets*: Once in, attackers may exfiltrate sensitive data or disrupt services. Keep your systems patched and stay vigilant! Follow @code2shell for more AppSec & Hacking content.

    Post summary

    The post announces CVE‑2023‑38646 as a privilege escalation flaw, highlights its broad impact and the availability of proof‑of‑concept exploits, but offers no concrete exploit code or evidence of active use.

    0000049
    3 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmetabasemetabase---
Appmetabasemetabase---

Explore more