CVE-2026-59826Disclosure(metabase / metabase)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch metabase metabase systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • metabase

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-07-09); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
metabase

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-07-09: 2Mentions · 2026-07-16: 2Mentions · 2026-07-17: 1Mentions · 2026-07-22: 1Patch / Workaround · 2026-07-16: 2Technical Details · 2026-07-16: 2Technical Details · 2026-07-17: 107-0907-1607-1707-22
Signal classification3 categories
Disclosure
233.3%
General
233.3%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-07-092
Disclosure1General1
2026-07-162
Patch2
2026-07-171
Disclosure1
2026-07-221
General1
Full discourse6 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-59826: Metabase: Arbitrary Code Execution via Database Connection Detail Bypass Critical Vulnerability Alert! Metabase is affected by CVE-2026-59826. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-59826 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-59826" Search Dork: app="Metabase" Exposure: 114.2k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJNZXRhYmFzZSI=&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260717 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The tweet announces CVE-2026-59826, a critical arbitrary code execution flaw in Metabase, providing a link to an analysis page and exposure counts, but lacking PoC, exploit details, or patch information.

    1703673.2K
    12.7K followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CVE-2026-59827 & CVE-2026-59826: Metabase has patched two critical vulnerabilities (CVSS 9.9 & 9.1) that could lead to remote code execution (RCE) through unsafe H2 deserialization. #CyberSecurity #CVE #Metabase #RCE #ThreatWire https://t.co/dERvlUZyMs

    Post summary

    The post announces that Metabase has released patches for two high‑severity CVEs affecting RCE via unsafe H2 deserialization.

    00030218
    1.3K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Metabase patched CVE-2026-59827 (CVSS 9.9) and CVE-2026-59826 (CVSS 9.1). These flaws enable remote code execution via unsafe H2 deserialization. #Metabase #RCE #CVE202659827 #Deserialization #H2Database http://securityonline.info/metabase-h2-rce-cve-2026-59827/

    Post summary

    Metabase has released patches for CVE‑2026‑59827 and CVE‑2026‑59826, both high‑severity RCE vulnerabilities involving unsafe H2 deserialization.

    00010347
    12.5K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Metabase ❗ CVE-2026-59827 ❗ CVE-2026-59826 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-metabase/ https://t.co/0uZPolTy9k

    Post summary

    The post lists two CVE identifiers for Metabase products and points to external sources for additional details, without providing technical specifics or attesting to exploitation or mitigation.

    00000181
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-59826 Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate un… https://www.cve.org/CVERecord?id=CVE-2026-59826 ----- Traducción: CVE-2026-59826 Met… http://infoflow.cloud`

    Post summary

    The tweet references CVE‑2026‑59826 and links to a CVE record, but provides no substantive details about the vulnerability, its exploitation, or mitigations.

    0000039
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-59826 Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate un… https://www.cve.org/CVERecord?id=CVE-2026-59826

    Post summary

    Metabase versions 1.55.0–1.61.2 suffer a CVE‑2026‑59826 input‑validation flaw, but the post gives only version ranges and no PoC, exploitation or detailed technical info.

    00000691
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmetabasemetabase---

Explore more