CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2023-38646: Metabase Pre-Authenticated RCE Vulnerability

August 8, 2026

CVE-2023-38646 is a critical vulnerability in Metabase that allows pre-authenticated remote code execution on affected installations. With a CVSS score of 9.8, it was addressed by Metabase approximately three years prior to the 2026 zero-day incident. The flaw could be exploited by unauthenticated attackers to execute arbitrary code, posing a severe risk to self-hosted instances.