CVE-2026-67208

CRITICAL

Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console

Title source: cna
STIX 2.1

Description

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute arbitrary commands, resulting in root-level code execution when running the stock Docker image.

References (2)

Core 2
Core References
Technical Description technical-description
Researcher Disclosure
https://github.com/somta/Juggle/issues/86

Scores

CVSS v3 9.8
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-1188 CWE-306
Status published
Products (1)
somta/Juggle < 1.6.0
Published Jul 30, 2026
Tracked Since Jul 31, 2026