SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-50147

HIGH · CVSS 7.6 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Metabase versions 1.57.0 to 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4 are vulnerable to a file read vulnerability that allows attackers with access to configure a database connection to exploit unsafe JDBC parameters, potentially exposing sensitive files from the server's filesystem. This could lead to unauthorized access to sensitive data, making it critical for organizations using affected versions to prioritize upgrading to the patched releases. Users of Metabase, particularly those managing database connections, should take immediate action to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-50147
Severity
HIGH
CVSS
7.6
EPSS
0.20%

Original NVD Description

Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metabase server's filesystem by adding unsafe JDBC parameters to a MySQL or MariaDB connection, causing the driver to read files from the Metabase host and expose the contents through queries against the connected database or through validation error messages. This issue is fixed in versions 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4.

Related CVEs

Other vulnerabilities affecting the same vendor(s)