← All CVEs NewScan detects
critical

CVE-2023-38646

Metabase pre-authentication remote code execution via a public setup token

Severity
critical
Affected product
Metabase
Affected versions
Metabase ≥ 0.43, < 0.43.7.2
Affected versions
Metabase ≥ 1.43, < 1.43.7.2
Affected versions
Metabase ≥ 0.44, < 0.44.7.1
Affected versions
Metabase ≥ 1.44, < 1.44.7.1
Affected versions
Metabase ≥ 0.45, < 0.45.4.1
Affected versions
Metabase ≥ 1.45, < 1.45.4.1
Affected versions
Metabase ≥ 0.46, < 0.46.6.1
Affected versions
Metabase ≥ 1.46, < 1.46.6.1
Fixed in
Metabase 0.43.7.2
Fixed in
Metabase 1.43.7.2
Fixed in
Metabase 0.44.7.1
Fixed in
Metabase 1.44.7.1
Fixed in
Metabase 0.45.4.1
Fixed in
Metabase 1.45.4.1
Fixed in
Metabase 0.46.6.1
Fixed in
Metabase 1.46.6.1
Added to NewScan
2026-08-11
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 0.43.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 1.43.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 0.44.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 1.44.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 0.45.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 1.45.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

Metabase pre-authentication remote code execution via the setup token (CVE-2023-38646, CVSS 9.8, exploited in the wild and CISA-listed): /api/setup/validate accepts the setup token that /api/session/properties publishes to ANY anonymous caller, and the H2 application database lets the attacker-supplied connection string run arbitrary commands as the Metabase user. Measured 2026-08-11: vulhub/metabase:0.46.6 serves the token anonymously and STILL serves it after setup completes, so the precondition is met on a normally configured instance - which is why this is a version range and not an exposure row (the exposure row next to it fires only on the never-configured case). Confirmed silent on metabase/metabase:v0.46.6.1, the patched sibling, over the same probe. 0.x is the OSS series and 1.x the Enterprise series with identical minor/patch numbering, hence the row pair per branch. Version-match only: confirming in-band would mean running code on the target.

COMPONENT VERSION RANGE

NewScan fingerprints Metabase from its response and reports this CVE when the detected version falls inside the affected range below.

The 1.46.x branch of CVE-2023-38646. See the 0.46 row for the advisory and the measured pair.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →