Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Exploit-CVE-2023-38646-Metabase — Exploit for the Remote Code Execution (RCE) vulnerability identified in Metabase versions before 0.46.6.1 (open source) and 1.46.6.1 (Enterprise). Authentication is not required for exploitation. | Kitploit
Tools/GitHubGitHub/userconnecting/exploit-cve-2023-38646-metabase
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubuserconnecting/exploit-cve-2023-38646-metabase

Exploit-CVE-2023-38646-Metabase

Exploit for the Remote Code Execution (RCE) vulnerability identified in Metabase versions before 0.46.6.1 (open source) and 1.46.6.1 (Enterprise). Authentication is not required for exploitation.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
12 years agoNot yet reviewed

Exploit CVE-2023-38646 Metabase before 0.46.6.1 (open source) and before 1.46.6.1 (Enterprise)


Exploit for the Remote Code Execution (RCE) vulnerability identified in Metabase versions before 0.46.6.1 (open source) and 1.46.6.1 (Enterprise). The vulnerability allows attackers to execute arbitrary commands on the server at the server's privilege level, and authentication is not required for exploitation.

To execute this exploit, you will need to obtain the setup-token. Navigate to /api/session/properties on the website, where you can find the setup-token.

This exploit code has been developed solely for educational purposes and to enhance cybersecurity practices. Any use for illicit purposes is entirely your own responsibility. It is recommended to use it only in environments where explicit authorization is granted to avoid any ethical or legal violations.

References:

  • CVE-2023-38646
  • packet storm
Download Tool