CVE-2026-59827Patch(metabase / metabase)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch metabase metabase systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • metabase

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-07-16); latest day: 2
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
metabase

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-07-09: 2Mentions · 2026-07-16: 3Mentions · 2026-07-22: 1Mentions · 2026-09-04: 2PoC Mentioned / Linked · 2026-07-16: 2PoC Mentioned / Linked · 2026-09-04: 1Exploit Tool / Code · 2026-09-04: 1Patch / Workaround · 2026-07-09: 2Patch / Workaround · 2026-07-16: 3Technical Details · 2026-07-16: 3Technical Details · 2026-09-04: 107-0907-1607-2209-04
Signal classification4 categories
Patch
450.0%
General
225.0%
Disclosure
112.5%
Exploit
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-07-092
Patch2
2026-07-163
Disclosure1Patch2
2026-07-221
General1
2026-09-042
Exploit1General1
Full discourse8 posts
  • ExploitGrid@exploitgrid
    Disclosure

    🚨 Critical Metabase RCE: CVE-2026-59827 (CVSS 9.9) Unsafe deserialization in H2 query handling → authenticated users get full RCE via the default Sample DB. Affected: 0.58.0–0.61.1.3 (OSS) Fix: Upgrade to 0.61.1.4+ Full writeup 👇 https://exploitgrid.net/blogs/cve-2026-59827-vuln-and-exploit-working

    Post summary

    A critical RCE vulnerability (CVE‑2026‑59827) in Metabase due to unsafe deserialization is disclosed, affecting OSS versions 0.58.0–0.61.1.3; a patch is available in 0.61.1.4+, with a detailed writeup linked for exploitation guidance.

    03040187
    40 followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CVE-2026-59827 & CVE-2026-59826: Metabase has patched two critical vulnerabilities (CVSS 9.9 & 9.1) that could lead to remote code execution (RCE) through unsafe H2 deserialization. #CyberSecurity #CVE #Metabase #RCE #ThreatWire https://t.co/dERvlUZyMs

    Post summary

    Metabase has released patches for CVE‑2026‑59827 and CVE‑2026‑59826, both scored CVSS 9.9 and 9.1, respectively, and potentially allowing remote code execution through unsafe H2 deserialization. No proof of active exploitation or PoC is mentioned.

    00030218
    1.3K followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-EDB-JNosaEB [CRITICAL/PoC] Linked: CVE-2026-59827 Metabase 0.61.0 - Authenticated Remote Code Execution 🔗 https://exploitgrid.net/exploits/9113d7c9-d6a0-4d06-8658-a7273108991f

    Post summary

    A PoC and functional exploit for CVE-2026-59827, targeting authenticated Remote Code Execution in Metabase 0.61.0, is available on ExploitGrid.

    1000071
    40 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2025-57819 CVE-2026-83548 CVE-2026-59827 CVE-2017-5638 CVE-2025-32958 ..🧵👇

    Post summary

    The digest lists several CVE identifiers without providing any exploitation details, patches, or other actionable information.

    1000067
    40 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Metabase patched CVE-2026-59827 (CVSS 9.9) and CVE-2026-59826 (CVSS 9.1). These flaws enable remote code execution via unsafe H2 deserialization. #Metabase #RCE #CVE202659827 #Deserialization #H2Database http://securityonline.info/metabase-h2-rce-cve-2026-59827/

    Post summary

    Metabase has released patches for CVE-2026-59827 and CVE-2026-59826, which allow remote code execution via unsafe H2 deserialization. The post includes a link to more details but does not discuss active exploitation or a full PoC.

    00010347
    12.5K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Metabase ❗ CVE-2026-59827 ❗ CVE-2026-59826 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-metabase/ https://t.co/0uZPolTy9k

    Post summary

    The tweet announces two new CVEvulnerabilities for Metabase and directs readers to an external link for more information.

    00000181
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-59827 Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 databas… https://www.cve.org/CVERecord?id=CVE-2026-59827 ----- Traducción: CVE-2026-59827 Met… http://infoflow.cloud`

    Post summary

    The tweet announces a CVE for Metabase and lists the fixed releases, serving as a patch notification without providing exploit or technical details.

    0000042
    91 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-59827 Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 databas… https://www.cve.org/CVERecord?id=CVE-2026-59827

    Post summary

    The entry identifies vulnerable Metabase versions up to 1.61.1.4 for CVE-2026-59827, implying those releases need patching, but provides no PoC, exploit, or active misuse details.

    00000647
    57.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmetabasemetabase---
Appmetabasemetabase---

Explore more