Metabase authenticated RCE via H2 native-query deserialization (CVE-2026-59827)
Exploit-DB entry 52680 (dated 3 September 2026) and Metabase advisory GHSA-w95f-x9v9-wv36 cover CVE-2026-59827: Metabase instances with an H2 database connection (including the default sample database) deserialize arbitrary Java objects from native H2 query result columns of type OTHER without validation. An authenticated user who can run native queries against an accessible H2 connection can execute OS commands on the Metabase host. Affected ranges in the exploit write-up include ≥0.58.0 <0.58.15, ≥0.59.0 <0.59.12, ≥0.60.0 <0.60.6.3, and ≥0.61.0 <0.61.1.4. Patch Metabase; remove or lock down sample/H2 connections; restrict who can run native SQL.
- Product
- Metabase
- Versions
- ≥0.58.0 <0.58.15; ≥0.59.0 <0.59.12; ≥0.60.0 <0.60.6.3; ≥0.61.0 <0.61.1.4 (per EDB/advisory ranges)
- Exploited in Australia?
- unknown
- Patch to
- Upgrade to fixed Metabase builds in each line; disable unused H2/sample DB; limit native-query permission
Primary: Metabase GHSA-w95f-x9v9-wv36 · Vendor: Metabase · CVE: CVE-2026-59827 · Exploit-DB 52680 (3 Sep 2026)
