Metabase A.I CyberSecurity Scoring
Metabase
Company Information
Website:http://www.metabase.com
Employees number:126
Number of followers:27,525
NAICS:518
Industry Type:Data Infrastructure and Analytics
Homepage:metabase.com
Metabase Risk Score (AI oriented)
Between 750 and 799
MetabaseData Infrastructure and Analytics
Updated:
27/04/2026
27/04/2026
750/1000
Fair
Baa
Metabase Global Score (TPRM)
xxxx
MetabaseData Infrastructure and Analytics
Score locked

MetabaseFair
Current Score
750Baa (FAIR)
01000
1 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750
MAY 2026
750
APRIL 2026
755
Vulnerability
27 Apr 2026 • Metabase
Metabase: PoC Exploit Released for Critical Metabase Enterprise RCE Vulnerability
Critical RCE Vulnerability in Metabase Enterprise Exploited in the Wild
750
CRITICAL-5
MET1777286018
Critical RCE Vulnerability in Metabase Enterprise Exploited in the Wild
Security researchers have disclosed a severe remote code execution (RCE) vulnerability in Metabase Enterprise, tracked as CVE-2026-33725, after a proof-of-concept (PoC) exploit was publicly released. The flaw, stemming from an H2 JDBC INIT injection weakness during serialization imports, allows unauthenticated attackers to execute arbitrary code or access sensitive files on vulnerable systems.
The vulnerability affects multiple Metabase Enterprise versions, including:
- 1.47.0–1.54.21
- 1.55.0–1.55.21
- 1.56.0–1.56.21
- 1.57.0–1.57.15
- 1.58.0–1.58.9
- 1.59.0–1.59.3
A Python-based PoC exploit, published by Hakai Security researcher Diego Tellaroli, automates the attack chain, increasing the risk of widespread exploitation. While the tool includes an educational disclaimer, its availability lowers the barrier for threat actors to launch automated attacks against exposed instances.
Metabase has released patched versions (1.59.4, 1.58.10, 1.57.16) to mitigate the flaw. Organizations unable to patch immediately are advised to restrict access to the Metabase admin interface, limit network exposure, and monitor logs for suspicious activity. Unpatched systems risk full compromise, data breaches, and potential lateral movement within enterprise networks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
755
FEBRUARY 2026
755
JANUARY 2026
755
DECEMBER 2025
755
NOVEMBER 2025
755
OCTOBER 2025
755
SEPTEMBER 2025
755
AUGUST 2025
755
JULY 2025
755
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Metabase ??
What was Metabase's A.I Rankiteo Cyber Score in May 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in April 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in March 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in February 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in January 2026 ??
What was Metabase's A.I Rankiteo Cyber Score in December 2025 ??
What was Metabase's A.I Rankiteo Cyber Score in November 2025 ??
What was Metabase's A.I Rankiteo Cyber Score in October 2025 ??
What was Metabase's A.I Rankiteo Cyber Score in September 2025 ??
What was Metabase's A.I Rankiteo Cyber Score in August 2025 ??
What was Metabase's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Metabase's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Metabase ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Metabase's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?