Improper access control in Metabase - CVE-2023-32680
Published: May 18, 2023 / Updated: May 5, 2026
Metabase
Metabase
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in SQL snippet permissions enforcement when editing SQL snippets through the API or the application UI. A remote user can edit a SQL snippet to disclose sensitive information.
User interaction is required when editing the metadata for a model based on a SQL question in the application UI.