CVE-2026-33725 is a vulnerability in Metabase Enterprise Edition affecting the POST /api/ee/serialization/import endpoint. In vulnerable Metabase Enterprise versions prior to 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, an authenticated administrator can supply a crafted serialization archive that injects an INIT property into the H2 JDBC connection specification. During a subsequent database sync, this attacker-controlled JDBC configuration causes arbitrary SQL execution. The issue can be leveraged for remote code execution and arbitrary file read. The vulnerable code path exists only in Metabase Enterprise; Metabase OSS is not affected. The advisory states that all Metabase Enterprise versions with serialization support, dating back to at least 1.47, are affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
POST /api/ee/serialization/import, and review Metabase hosts for signs of malicious serialization imports or unexpected database sync activity until patching is completed.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact proof-of-concept exploit for CVE-2026-33725 targeting Metabase Enterprise. It contains two files: a README describing the vulnerability, affected versions, and references; and a single Python exploit script, exploit.py, which is the operational entry point. The exploit abuses the Metabase EE serialization import feature by uploading a crafted tar.gz archive containing a malicious database YAML definition under export/databases/<name>/<name>.yaml. The YAML sets engine: h2 and injects attacker-controlled content into the H2 JDBC subname/INIT parameter. After import, the script forces Metabase to connect to the imported database by calling /api/database/<id>/sync_schema, /api/database/<id>/rescan_values, and /api/dataset with a native SELECT 1 query. This causes the H2 INIT payload to execute. The script supports two modes: 1. Safe/proof mode: writes a marker file to a target path (default /tmp/metabase_poc_pwned.txt) using H2 CSVWRITE, demonstrating arbitrary file write. 2. RCE mode (--cmd): generates Clojure code that invokes clojure.java.shell/sh with /bin/sh -c <command>, writes that code to a temporary file via CSVWRITE, creates an H2 alias to clojure.lang.Compiler.loadFile, and loads the file to execute the supplied OS command. Operationally, the exploit requires a Metabase base URL and an admin session token. It first probes /api/ee/serialization/import to distinguish OSS vs EE behavior and optionally supports an HTTP proxy. It also attempts to delete any preexisting database with the same generated name before importing the malicious archive. Overall, this is a real exploit rather than a detector: it performs authenticated remote exploitation over HTTP against Metabase EE administrative APIs and can achieve arbitrary file write or command execution on vulnerable servers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.