Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
9.9
CVE-2026-59827EXPLOITED
metaba · metabase

Metabase: Unsafe Deserialization of H2 Query Results

Description

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.

Affected Products

VendorProductVersions
metabametabase>= 1.58.0, < 1.58.15, >= 1.59.0, < 1.59.12, >= 1.60.0, < 1.60.6.3, >= 1.61.0, < 1.61.1.4

References

  • https://github.com/metabase/metabase/security/advisories/GHSA-w95f-x9v9-wv36(x_refsource_CONFIRM)
  • https://github.com/metabase/metabase/commit/00f42511fe3bc4385652a2e96862ee6fd7d42cf8(x_refsource_MISC)
  • https://github.com/metabase/metabase/releases/tag/v0.58.15(x_refsource_MISC)
  • https://github.com/metabase/metabase/releases/tag/v0.59.12(x_refsource_MISC)
  • https://github.com/metabase/metabase/releases/tag/v0.60.6.3(x_refsource_MISC)
  • https://github.com/metabase/metabase/releases/tag/v0.61.1.4(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB45d ago
CVE-2026-59827 | Metabase up to 1.58.14/1.59.11 H2 Database Query deserialization
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-502
PublishedJul 9, 2026
Last enriched45d agov2
Trending Score0
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-72898EXPKEV
Metabase SQL injection via password reset endpoint
Trending: 46
CRITICALCVE-2026-72899
Metabase SQL injection via public card or dashboard
Trending: 14
MEDIUMCVE-2026-72900
Metabase information exposure
Trending: 7
CRITICALCVE-2026-50148
Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
Trending: 1
CRITICALCVE-2026-59826EXP
Metabase: Arbitrary Code Execution via Database Connection Detail Bypass

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 9, 2026
Discovered by ZDM
Jul 9, 2026
Updated: affectedVersions, severity, activelyExploited
Jul 9, 2026
Actively Exploited
Jul 9, 2026

Version History

v2
Last enriched 45d ago
v2Tier C45d ago

Updated affected versions to < 1.58.15 and < 1.59.12, changed severity to HIGH, and noted that the exploit is not available.

affectedVersionsseverityactivelyExploited
via VulDB
v145d ago

Initial creation