Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
7.6
CVE-2026-50147EXPLOITED
metaba · metaba

Metabase: Arbitrary File Read via MySQL Connection Property Injection

Description

Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metabase server's filesystem by adding unsafe JDBC parameters to a MySQL or MariaDB connection, causing the driver to read files from the Metabase host and expose the contents through queries against the connected database or through validation error messages. This issue is fixed in versions 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4.

Affected Products

VendorProductVersions
metabametaba>= 1.57.0, < 1.57.19.1, >= 1.58.0, < 1.58.14.1, >= 1.59.0, < 1.59.10, >= 1.60.0, < 1.60.4, >= 1.59.0, < 1.59.9, >= 1.60.0, < 1.60.3

References

  • https://github.com/metabase/metabase/security/advisories/GHSA-mfpj-crjq-xrcp(x_refsource_CONFIRM)

Related News (1 articles)

Tier C
VulDB28d ago
CVE-2026-50147 | Metabase up to 1.59.9/1.60.3 Database Connection information disclosure
→ No new info (linked only)
CVSS 3.17.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-88
PublishedJul 15, 2026
Last enriched28d agov2
Trending Score1
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-72898EXPKEV
Metabase SQL injection via password reset endpoint
Trending: 119
CRITICALCVE-2026-72899
Metabase SQL injection via public card or dashboard
Trending: 49
MEDIUMCVE-2026-72900
Metabase information exposure
Trending: 30
CRITICALCVE-2026-50148
Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
Trending: 2
CRITICALCVE-2026-59826EXP
Metabase: Arbitrary Code Execution via Database Connection Detail Bypass

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Actively Exploited
Jul 15, 2026
Updated: affectedVersions, activelyExploited
Jul 15, 2026

Version History

v2
Last enriched 28d ago
v2Tier C28d ago

Updated affected versions to include 1.59.9 and 1.60.3, and marked the vulnerability as actively exploited.

affectedVersionsactivelyExploited
via VulDB
v128d ago

Initial creation