← Zurück zur CVE-Suche

CVE-2026-59826

Metabase

Beschreibung

Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.

CVSS 9.1EPSS 0.391%Risiko 0.94
Quelle öffnen
Veröffentlicht
2026-07-09 18:16:57
Betroffene Versionen
>=1.55.0, <1.58.15.1, >=1.59.0, <1.59.12, >=1.60.0, <1.60.6.3, >=1.61.0, <1.61.2
Typ
Webanwendung
Zuletzt geändert
2026-07-30 14:32:02
Vektor
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H