PoC Exploit Released for Critical Metabase Enterprise RCE Vulnerability
ID: feaea7e0-ac29-5387-9aae-b3101a6cd014
STIX ID: report--feaea7e0-ac29-5387-9aae-b3101a6cd014
Feed Name: Cyber Press
Threat Score
**Critical RCE in Metabase Enterprise (CVE-2026-33725)** — A deserialization/H2 JDBC INIT injection flaw allows attackers to execute arbitrary commands and access files via specially crafted import files; a public Python PoC is available, multiple release branches are affected, and vendors have released patched versions (e.g., 1.59.4, 1.58.10, 1.57.16) with guidance to patch immediately or restrict access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
