CVE-2026-33725PoC(metabase / metabase)

HIGHCVSS 7.2 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch metabase metabase systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve Remote Code Execution (RCE) and Arbitrary File Read via the `POST /api/ee/serialization/import` endpoint. A crafted serialization archive injects an `INIT` property into the H2 JDBC spec, which can execute arbitrary SQL during a database sync. We confirmed this was possible on Metabase Cloud. This only affects Metabase Enterprise. Metabase OSS lacks the affected codepaths. All versions of Metabase Enterprise that have serialization, which dates back to at least version 1.47, are affected. Metabase Enterprise versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4 patch the issue. As a workaround, disable the serialization import endpoint in their Metabase instance to prevent access to the vulnerable codepaths.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • metabase

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 16 mentions across 12 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 9 signals
  • PoC mentioned or linked in 11 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 12 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 7d ago at 3 mentions (2026-04-27); latest day: 1
  • 16 total mentions across 12 days

Affected systems

Vendors
Products
metabase

Deep dive

Activity timeline16 mentions / 12d
01223Mentions · 2026-03-27: 2Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-04-26: 1Mentions · 2026-04-27: 3Mentions · 2026-04-28: 1Mentions · 2026-05-02: 1Mentions · 2026-05-05: 1Mentions · 2026-05-07: 1Mentions · 2026-05-10: 1Mentions · 2026-05-23: 2Mentions · 2026-07-16: 1PoC Mentioned / Linked · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-24: 1PoC Mentioned / Linked · 2026-04-26: 1PoC Mentioned / Linked · 2026-04-27: 2PoC Mentioned / Linked · 2026-04-28: 1PoC Mentioned / Linked · 2026-05-05: 1PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-05-10: 1PoC Mentioned / Linked · 2026-05-23: 2Exploit Tool / Code · 2026-04-23: 1Exploit Tool / Code · 2026-04-24: 1Exploit Tool / Code · 2026-04-26: 1Exploit Tool / Code · 2026-04-27: 1Exploit Tool / Code · 2026-04-28: 1Exploit Tool / Code · 2026-05-07: 1Exploit Tool / Code · 2026-05-10: 1Exploit Tool / Code · 2026-05-23: 2Active Exploitation · 2026-04-27: 1Active Exploitation · 2026-05-23: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-04-27: 2Patch / Workaround · 2026-05-10: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 3Technical Details · 2026-04-28: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-23: 203-2704-2304-2404-2604-2704-2805-0205-0505-0705-1005-2307-16
Signal classification6 categories
PoC
531.3%
Disclosure
318.8%
General
318.8%
Exploit
212.5%
Active Exploitation
212.5%
Patch
16.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-272
Disclosure1General1
2026-04-231
Exploit1
2026-04-241
Exploit1
2026-04-261
PoC1
2026-04-273
Active Exploitation1Disclosure1PoC1
2026-04-281
Disclosure1
2026-05-021
General1
2026-05-051
PoC1
2026-05-071
PoC1
2026-05-101
Patch1
2026-05-232
Active Exploitation1PoC1
2026-07-161
General1
Full discourse16 posts
  • Co11ateral@co11ateral
    PoC

    CVE-2026-33725 - RCE/LFI in MetaBase https://github.com/hakaioffsec/CVE-2026-33725 #cve #exploit #lfi #rce https://t.co/BJqu03s22j

    Post summary

    The tweet shares a PoC for CVE‑2026‑33725, highlighting an RCE/LFI flaw in MetaBase via a GitHub link, but lacks evidence of active exploitation, patches, or debunking.

    0240119607.6K
    8.4K followersView on X
  • blueblue@piedpiper1616
    Exploit

    GitHub - hakaioffsec/CVE-2026-33725: Exploit for CVE-2026-33725 - Remote Code Execution and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Import · GitHub - https://github.com/hakaioffsec/CVE-2026-33725

    Post summary

    The GitHub repository hosts an exploit for CVE‑2026‑33725 that demonstrates RCE and file read via H2 JDBC INIT injection, but it does not mention active exploitation or availability of a patch.

    0711371.5K
    5.5K followersView on X
  • Clandestine@akaclandestine
    Exploit

    GitHub - hakaioffsec/CVE-2026-33725: Exploit for CVE-2026-33725 - Remote Code Execution and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Import · GitHub https://github.com/hakaioffsec/CVE-2026-33725

    Post summary

    A GitHub repository provides a functional exploit and PoC that demonstrates remote code execution and arbitrary file read via H2 JDBC INIT injection in an EE serialization import.

    1401661.8K
    62.1K followersView on X
  • Hakai Offsec@HakaiOffsec
    PoC

    Em nossa análise mais recente, mergulhamos na CVE-2026-33725, uma vulnerabilidade de alta criticidade no Metabase Enterprise que permite a execução remota de comandos no servidor. A partir de uma análise técnica da rota de importação de arquivos YAML, mostraremos na prática como a falta de sanitização em parâmetros da conexão JDBC torna a plataforma vulnerável. Quer entender o impacto real dessa falha, o vetor de exploração envolvendo o banco H2 e como proteger seu ambiente? Confira o artigo. EN - https://hakaisecurity.io/en-cve-2026-33725-technical-analysis-and-proof-of-concept/research-blog/ PT-BR - https://hakaisecurity.io/cve-2026-33725-technical-analysis-and-proof-of-concept/research-blog/ Autores: Diego Tellaroli ( @diegotellaroli ) Guilherme D'ávila ( @neosian3301 )

    Post summary

    The post announces a technical analysis of CVE‑2026‑33725 in Metabase Enterprise, highlighting its remote code execution flaw and linking to a proof‑of‑concept.

    00052287
    1.2K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    TL;DR Metabase Enterprise suffers a critical pre-authentication RCE vulnerability (CVE-2026-33725) via H2 JDBC INIT injection during serialization imports. A public Python-based exploit by security researcher Diego Tellaroli (Hakai Security) is actively circulating as of 7…

    Post summary

    Metabase Enterprise’s critical pre‑authentication RCE (CVE‑2026‑33725) is being actively exploited in the wild by a public Python exploit that leverages an H2 JDBC INIT injection during serialization imports.

    1000071
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-33725 · 1.47.0 → 1.54.21 Metabase Unauthenticated RCE: H2 JDBC Injection Goes Public With Working Exploit

    Post summary

    The post announces a publicly available working exploit for CVE‑2026‑33725, an unauthenticated RCE via H2 JDBC injection in Metabase versions 1.47.0 to 1.54.21, with no patch or real‑world exploitation referenced.

    1000063
    227 followersView on X
  • iototsecnews@iototsecnews
    PoC

    Metabase Enterprise の脆弱性 CVE-2026-33725 が FIX:PoC エクスプロイト公開でリスク急増 https://iototsecnews.jp/2026/04/27/metabase-enterprise-rce-flaw-now-has-public-proof-of-concept-exploit/ Metabase Enterprise の脆弱性 CVE-2026-33725 は、 データの取り込みを行うシリアライズ・インポート処理の不備に起因します。 本来は、安全に処理されるべきインポート・ファイルに、 データベースを操作する不正な命令が紛れ込むと、 攻撃者の意図通りにサーバが動かされてしまいます。 特に H2 JDBC INIT という設定の隙を突かれることで、 遠隔からコードが実行されたり機密ファイルが読み取られたりする危険があります。 ご利用のチームは、ご注意ください。 #CVE202633725 #Exploit #Metabase #PoC #Vulnerability

    Post summary

    Metabase Enterprise CVE‑2026‑33725 enables remote code execution through malicious import files, and a public PoC exploit has been released, sharply increasing risk for users.

    0100098
    487 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-33725: Metabase Enterprise Serialization Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04pPrX90

    Post summary

    The snippet only provides a CVE title and a generic link without any concrete technical, exploit, or mitigation details.

    0000048
    32 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    🚨 CVE-2026-33725 (Metabase Enterprise v1.47–1.59.3): RCE via H2 JDBC INIT injection in serialization imports. PoC live on GitHub. Full DB read + arbitrary file access on your BI server. Most orgs unpatched. Upgrade to v1.59.4+ NOW. #ZeroDay #Metabase

    Post summary

    Metabase Enterprise users are warned of CVE‑2026‑33725, a critical RCE through H2 JDBC INIT injection; a PoC exists on GitHub and a patch (v1.59.4) is released, urging immediate upgrade.

    0000067
    197 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-33725: Metabase Enterprise Serialization Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04fbVJv0

    Post summary

    The snippet provides only a CVE reference and a link, lacking any actionable or detailed information.

    0000036
    29 followersView on X
  • N45HT@N45HTOfficial
    Disclosure

    [CVE-2026-33725] RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization Import 🔗 https://github.com/hakaioffsec/CVE-2026-33725 🔗 https://nvd.nist.gov/vuln/detail/CVE-2026-33725 🔗 https://github.com/metabase/metabase/security/advisories/GHSA-fppj-vcm3-w229 https://t.co/Dmmwbk0EZo

    Post summary

    A new vulnerability (CVE-2026-33725) allows RCE via H2 JDBC injection in Metabase, with PoC code available on GitHub, but no active exploitation or patch details are mentioned.

    0000052
    71 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-33725: Metabase RCE Flaw Exposes Enterprise Servers https://thecybrdef.com/cve-2026-33725-metabase-rce-vulnerability/

    Post summary

    The text announces the discovery of CVE‑2026‑33725, a remote code execution flaw in Metabase enterprise servers, without providing Proof‑of‑Concept, exploit code, patch details, or evidence of active exploitation.

    0000055
    7 followersView on X
  • CyberTech Insights@CyberTech_In
    PoC

    Critical RCE flaw (CVE-2026-33725) in Metabase Enterprise exposed as a public PoC exploit increases attack risk. Unpatched systems are highly vulnerable. Immediate updates are strongly advised. 𝐑𝐞𝐚𝐝 𝐟𝐮𝐥𝐥 𝐬𝐭𝐨𝐫𝐲 : https://cybertechnologyinsights.com/cybersecurity/metabase-rce-flaw-exposed-as-poc-exploit-goes-public/ https://t.co/8dOrlbFrPx

    Post summary

    CVE‑2026‑33725, a critical RCE vulnerability in Metabase Enterprise, has a publicly available PoC exploit and urges unpatched systems to apply updates immediately.

    00000134
    19 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Active Exploitation

    🚨 #CVE-2026-33725: Public Metabase Enterprise RCE Exploit Released – Patch Immediately Before Mass Exploitation Begins + Video https://undercodetesting.com/cve-2026-33725-public-metabase-enterprise-rce-exploit-released-patch-immediately-before-mass-exploitation-begins-video/ Educational Purposes!

    Post summary

    The tweet announces that CVE‑2026‑33725 — a Remote Code Execution flaw in Metabase Enterprise — is actively being exploited worldwide, offers details of a released exploit, and urges immediate patching.

    0000085
    499 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33725 Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, an… https://www.cve.org/CVERecord?id=CVE-2026-33725

    Post summary

    The post announces CVE-2026-33725 for Metabase Enterprise, indicating that versions prior to 1.54.22/1.55.22/1.56.22/1.57.16/1.58.10 are affected and that newer releases contain a fix.

    00000110
    56.9K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33725 📊 Severity: 7.2 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33725 #CVE-2026-33725 #CVE #High #CyberSecurity #InfoSec https://t.co/cm8R2l5riS

    Post summary

    A tweet announces CVE-2026-33725 with a high severity rating, but lacks any details on exploitation, mitigation, or technical specifics.

    0000028
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmetabasemetabase---

Explore more