Impact
Metabase has a defect that permits an attacker who is authenticated but holds only low-level privileges to read the entire application database. vulnerability stems from missing authorization checks when accessing database content, allowing privileged users to bypass restrictions. This can lead to widespread exposure of sensitive data stored in the application, compromising confidentiality and potentially revealing personal or proprietary information.
Affected Systems
The flaw affects the Metabase application. Any installation of Metabase that includes the default database schema is susceptible, regardless of deployment environment. No specific version information is provided, so all current releases are potentially impacted until mitigated.
Risk and Exploitability
The CVSS score for this issue is 7.1, indicating a substantial impact. No EPSS value is available, so the exploitation probability cannot be quantified with current data. The vulnerability is not listed in the CISA KEV catalog, but the requirement for merely possessing a low-privilege account makes it potentially attractive to attackers inside an organization. Exploitation likely follows a path where an authenticated user accesses privileged endpoints that are incorrectly guarded, inadvertently retrieving the full database contents, and the attack vector is inferred from the description; the vulnerability description only indicates that a low‑privileged attacker can read the entire application database.
OpenCVE Enrichment