logo

PoC Exploit Released for Critical Metabase Enterprise RCE Vulnerability

ID: feaea7e0-ac29-5387-9aae-b3101a6cd014

STIX ID: report--feaea7e0-ac29-5387-9aae-b3101a6cd014

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: AnuPriya

...
...

**Critical RCE in Metabase Enterprise (CVE-2026-33725)** — A deserialization/H2 JDBC INIT injection flaw allows attackers to execute arbitrary commands and access files via specially crafted import files; a public Python PoC is available, multiple release branches are affected, and vendors have released patched versions (e.g., 1.59.4, 1.58.10, 1.57.16) with guidance to patch immediately or restrict access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.