CVE-2026-59826

CRITICAL

Metabase: Arbitrary Code Execution via Database Connection Detail Bypass

Title source: cna
STIX 2.1

Description

Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.

Scores

CVSS v3 9.1
EPSS 0.0039
EPSS Percentile 31.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (5)
metabase/metabase 1.55.0 - 1.58.15.1
metabase/metabase >= 1.55.0, < 1.58.15.1
metabase/metabase >= 1.59.0, < 1.59.12
metabase/metabase >= 1.60.0, < 1.60.6.3
metabase/metabase >= 1.61.0, < 1.61.2
Published Jul 09, 2026
Tracked Since Jul 09, 2026