Vulnerability
Published 2026-09-03
Verified 2026-09-19

Metabase authenticated RCE via H2 native-query deserialization (CVE-2026-59827)

Exploit-DB entry 52680 (dated 3 September 2026) and Metabase advisory GHSA-w95f-x9v9-wv36 cover CVE-2026-59827: Metabase instances with an H2 database connection (including the default sample database) deserialize arbitrary Java objects from native H2 query result columns of type OTHER without validation. An authenticated user who can run native queries against an accessible H2 connection can execute OS commands on the Metabase host. Affected ranges in the exploit write-up include ≥0.58.0 <0.58.15, ≥0.59.0 <0.59.12, ≥0.60.0 <0.60.6.3, and ≥0.61.0 <0.61.1.4. Patch Metabase; remove or lock down sample/H2 connections; restrict who can run native SQL.

Product
Metabase
Versions
≥0.58.0 <0.58.15; ≥0.59.0 <0.59.12; ≥0.60.0 <0.60.6.3; ≥0.61.0 <0.61.1.4 (per EDB/advisory ranges)
Exploited in Australia?
unknown
Patch to
Upgrade to fixed Metabase builds in each line; disable unused H2/sample DB; limit native-query permission

Primary: Metabase GHSA-w95f-x9v9-wv36 · Vendor: Metabase · CVE: CVE-2026-59827 · Exploit-DB 52680 (3 Sep 2026)

vulnerabilities cloud