SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-59827

CRITICAL · CVSS 9.9 EPSS 0.62% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

Metabase instances using an H2 database connection prior to specified versions are vulnerable to arbitrary code execution due to improper deserialization of Java objects in native query results. This critical vulnerability allows authenticated users to execute malicious code on the Metabase server, posing a significant risk to data integrity and system security. Organizations utilizing affected versions of Metabase should prioritize immediate updates to the patched versions to mitigate this threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59827
Severity
CRITICAL
CVSS
9.9
EPSS
0.62%
Java

Original NVD Description

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.

Related CVEs

Other vulnerabilities affecting the same vendor(s)