EIP-2026-103298

PRE-CVE

Metabase 0.46.6 - Pre-Auth Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103298. PoCs published by Musyoka Ian.

AI-analyzed exploit summary This exploit leverages CVE-2023-38646 to achieve pre-authentication remote code execution in Metabase 0.46.6 by abusing the setup validation endpoint to inject a malicious H2 database trigger. The trigger executes arbitrary Java code, fetching and running a reverse shell payload.

Description

Metabase 0.46.6 - Pre-Auth Remote Code Execution

Exploits (1)

exploitdb WORKING POC
by Musyoka Ian · pythonwebappslinux
https://www.exploit-db.com/exploits/51797

This exploit leverages CVE-2023-38646 to achieve pre-authentication remote code execution in Metabase 0.46.6 by abusing the setup validation endpoint to inject a malicious H2 database trigger. The trigger executes arbitrary Java code, fetching and running a reverse shell payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Metabase 0.46.6
No auth needed
Prerequisites: Network access to the Metabase instance · Attacker-controlled HTTP server to host payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026