EIP-2026-103298
PRE-CVEMetabase 0.46.6 - Pre-Auth Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103298. PoCs published by Musyoka Ian.
AI-analyzed exploit summary This exploit leverages CVE-2023-38646 to achieve pre-authentication remote code execution in Metabase 0.46.6 by abusing the setup validation endpoint to inject a malicious H2 database trigger. The trigger executes arbitrary Java code, fetching and running a reverse shell payload.
Description
Metabase 0.46.6 - Pre-Auth Remote Code Execution
Exploits (1)
This exploit leverages CVE-2023-38646 to achieve pre-authentication remote code execution in Metabase 0.46.6 by abusing the setup validation endpoint to inject a malicious H2 database trigger. The trigger executes arbitrary Java code, fetching and running a reverse shell payload.