ThreatWire[verified]@ThreatWire_Patch
Metabase has released patches for CVE‑2026‑59827 and CVE‑2026‑59826, both scored CVSS 9.9 and 9.1, respectively, and potentially allowing remote code execution through unsafe H2 deserialization. No proof of active exploitation or PoC is mentioned.
ExploitGrid@exploitgridDisclosure
A critical RCE vulnerability (CVE‑2026‑59827) in Metabase due to unsafe deserialization is disclosed, affecting OSS versions 0.58.0–0.61.1.3; a patch is available in 0.61.1.4+, with a detailed writeup linked for exploitation guidance.
ExploitGrid@exploitgridExploit
A PoC and functional exploit for CVE-2026-59827, targeting authenticated Remote Code Execution in Metabase 0.61.0, is available on ExploitGrid.
ExploitGrid@exploitgridGeneral
The digest lists several CVE identifiers without providing any exploitation details, patches, or other actionable information.
Daily CyberSecurity@Daily_CyberSecPatch
Metabase has released patches for CVE-2026-59827 and CVE-2026-59826, which allow remote code execution via unsafe H2 deserialization. The post includes a link to more details but does not discuss active exploitation or a full PoC.
CERT-PY@CERTpyGeneral
The tweet announces two new CVEvulnerabilities for Metabase and directs readers to an external link for more information.
Infoflowcloud@infoflowcloudPatch
The tweet announces a CVE for Metabase and lists the fixed releases, serving as a patch notification without providing exploit or technical details.
CVE@CVEnewPatch
The entry identifies vulnerable Metabase versions up to 1.61.1.4 for CVE-2026-59827, implying those releases need patching, but provides no PoC, exploit, or active misuse details.