Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5015 articles · 188889 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-59826EXPLOITED
metaba · metabase

Metabase: Arbitrary Code Execution via Database Connection Detail Bypass

Description

Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.

Affected Products

VendorProductVersions
metabametabase>= 1.55.0, < 1.58.15.1, >= 1.59.0, < 1.59.12, >= 1.60.0, < 1.60.6.3, >= 1.61.0, < 1.61.2

References

  • https://github.com/metabase/metabase/security/advisories/GHSA-8wx2-rxp2-4x35(x_refsource_CONFIRM)
  • https://github.com/metabase/metabase/commit/74032e5e0a5a70dc45a6a744d37b9ba24eee8d01(x_refsource_MISC)
  • https://github.com/metabase/metabase/releases/tag/v0.58.15.1(x_refsource_MISC)
  • https://github.com/metabase/metabase/releases/tag/v0.59.12(x_refsource_MISC)
  • https://github.com/metabase/metabase/releases/tag/v0.60.6.3(x_refsource_MISC)
  • https://github.com/metabase/metabase/releases/tag/v0.61.2(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB33d ago
CVE-2026-59826 | Metabase up to 1.58.15.1/1.59.11/1.60.6.2/1.61.1 H2 Database Connection code injection
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-94
PublishedJul 9, 2026
Last enriched33d agov2
Trending Score0
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-72898EXPKEV
Metabase SQL injection via password reset endpoint
Trending: 121
CRITICALCVE-2026-72899
Metabase SQL injection via public card or dashboard
Trending: 50
MEDIUMCVE-2026-72900
Metabase information exposure
Trending: 30
CRITICALCVE-2026-50148
Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
Trending: 2
HIGHCVE-2026-50147EXP
Metabase: Arbitrary File Read via MySQL Connection Property Injection
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 9, 2026
Discovered by ZDM
Jul 9, 2026
Updated: affectedVersions, activelyExploited
Jul 9, 2026
Actively Exploited
Jul 10, 2026

Version History

v2
Last enriched 33d ago
v2Tier C33d ago

Updated vendor and product names, added affected versions, and corrected exploit availability status.

affectedVersionsactivelyExploited
via VulDB
v133d ago

Initial creation