CVE-2026-50148
CRITICALMetabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
Title source: cnaDescription
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in versions 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/metabase/metabase/security/advisories/GHSA-r6x2-rchx-q9g9
Scores
CVSS v3
10.0
EPSS
0.0044
EPSS Percentile
36.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-73
Status
published
Products (8)
metabase/metabase
1.54.0 - 1.54.24
metabase/metabase
>= 1.54.0, < 1.54.24
metabase/metabase
>= 1.55.0, < 1.55.24
metabase/metabase
>= 1.56.0, < 1.56.25
metabase/metabase
>= 1.57.0, < 1.57.19
metabase/metabase
>= 1.58.0, < 1.58.14
metabase/metabase
>= 1.59.0, < 1.59.10
metabase/metabase
>= 1.60.0, < 1.60.4
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026