Data Exposure in Metabase Enterprise Edition Affects User Permissions
CVE-2025-27141
What is CVE-2025-27141?
In the Metabase Enterprise Edition, users with impersonation permissions can inadvertently access cached query results not meant for them. Specifically, if a query is executed by a user allowing caching, and an impersonated user subsequently runs the same query, the impersonated user can view cached results that contain data they are not authorized to see. This flaw affects versions 1.47.0 through 1.49.X, with remedial updates included in versions 1.50.36, 1.51.14, 1.52.11, and 1.53.2. Users are urged to upgrade or disable caching to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
metabase >= 1.47.0, < 1.50.36 < 1.47.0, 1.50.36
metabase >= 1.51.0, < 1.51.14 < 1.51.0, 1.51.14
metabase >= 1.52.0, < 1.51.11 < 1.52.0, 1.51.11
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
