CVE-2023-38646
Metabase pre-authentication remote code execution via a public setup token
- Severity
- critical
- Affected product
- Metabase
- Affected versions
- Metabase ≥ 0.43, < 0.43.7.2
- Affected versions
- Metabase ≥ 1.43, < 1.43.7.2
- Affected versions
- Metabase ≥ 0.44, < 0.44.7.1
- Affected versions
- Metabase ≥ 1.44, < 1.44.7.1
- Affected versions
- Metabase ≥ 0.45, < 0.45.4.1
- Affected versions
- Metabase ≥ 1.45, < 1.45.4.1
- Affected versions
- Metabase ≥ 0.46, < 0.46.6.1
- Affected versions
- Metabase ≥ 1.46, < 1.46.6.1
- Fixed in
- Metabase 0.43.7.2
- Fixed in
- Metabase 1.43.7.2
- Fixed in
- Metabase 0.44.7.1
- Fixed in
- Metabase 1.44.7.1
- Fixed in
- Metabase 0.45.4.1
- Fixed in
- Metabase 1.45.4.1
- Fixed in
- Metabase 0.46.6.1
- Fixed in
- Metabase 1.46.6.1
- Added to NewScan
- 2026-08-11
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 0.43.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 1.43.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 0.44.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 1.44.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 0.45.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 1.45.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
Metabase pre-authentication remote code execution via the setup token (CVE-2023-38646, CVSS 9.8, exploited in the wild and CISA-listed): /api/setup/validate accepts the setup token that /api/session/properties publishes to ANY anonymous caller, and the H2 application database lets the attacker-supplied connection string run arbitrary commands as the Metabase user. Measured 2026-08-11: vulhub/metabase:0.46.6 serves the token anonymously and STILL serves it after setup completes, so the precondition is met on a normally configured instance - which is why this is a version range and not an exposure row (the exposure row next to it fires only on the never-configured case). Confirmed silent on metabase/metabase:v0.46.6.1, the patched sibling, over the same probe. 0.x is the OSS series and 1.x the Enterprise series with identical minor/patch numbering, hence the row pair per branch. Version-match only: confirming in-band would mean running code on the target.
COMPONENT VERSION RANGE
NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.
The 1.46.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →