Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5015 articles · 188889 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-50148
metaba · metaba

Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write

Description

Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in versions 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4.

Affected Products

VendorProductVersions
metabametaba>= 1.54.0, < 1.54.24, >= 1.55.0, < 1.55.24, >= 1.56.0, < 1.56.25, >= 1.57.0, < 1.57.19, >= 1.58.0, < 1.58.14, >= 1.59.0, < 1.59.10, >= 1.60.0, < 1.60.4

References

  • https://github.com/metabase/metabase/security/advisories/GHSA-r6x2-rchx-q9g9(x_refsource_CONFIRM)

Related News (1 articles)

Tier C
VulDB28d ago
CVE-2026-50148 | Metabase up to 1.60.3 Snowflake JDBC driver permission
→ No new info (linked only)
CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-73
PublishedJul 15, 2026
Last enriched28d agov2
Trending Score2
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-72898EXPKEV
Metabase SQL injection via password reset endpoint
Trending: 121
CRITICALCVE-2026-72899
Metabase SQL injection via public card or dashboard
Trending: 50
MEDIUMCVE-2026-72900
Metabase information exposure
Trending: 30
HIGHCVE-2026-50147EXP
Metabase: Arbitrary File Read via MySQL Connection Property Injection
Trending: 1
CRITICALCVE-2026-59826EXP
Metabase: Arbitrary Code Execution via Database Connection Detail Bypass

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Updated: affectedVersions, severity
Jul 15, 2026

Version History

v2
Last enriched 28d ago
v2Tier C28d ago

Updated vendor and product names, adjusted affected versions to include up to 1.60.3, and changed severity to HIGH.

affectedVersionsseverity
via VulDB
v128d ago

Initial creation