SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-50148

CRITICAL · CVSS 10 EPSS 0.43% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Metabase versions from 1.54.0 to 1.60.4 are vulnerable to remote code execution due to a flaw in the Snowflake JDBC driver, allowing users with permission to add or edit database connections to write arbitrary files on the server. This critical vulnerability can lead to the replacement of essential Metabase database driver files, compromising the integrity of the application. Organizations using affected versions should prioritize updating to the fixed releases to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-50148
Severity
CRITICAL
CVSS
10
EPSS
0.43%

Original NVD Description

Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in versions 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4.

Related CVEs

Other vulnerabilities affecting the same vendor(s)