CVE-2026-67208
CRITICALJuggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
Title source: cnaDescription
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute arbitrary commands, resulting in root-level code execution when running the stock Docker image.
References (2)
Core 2
Core References
Technical Description technical-description
Researcher Disclosure
https://github.com/somta/Juggle/issues/86
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/juggle-unauthenticated-rce-via-exposed-h2-console
Scores
CVSS v3
9.8
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-1188
CWE-306
Status
published
Products (1)
somta/Juggle
< 1.6.0
Published
Jul 30, 2026
Tracked Since
Jul 31, 2026