A critical vulnerability was discovered in Metabase, an open-source business intelligence and embedded analytics tool. The issue, tracked as CVE-2026-50148, allows a Metabase user with permission to add or edit a database connection to achieve remote code execution on the Metabase server. This is possible by configuring a Snowflake connection to an attacker-controlled server, exploiting a flaw in the Snow [truncated]
Metabase is vulnerable to code execution. Instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation. An authenticated user who can run native H2 queries can execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4. The vu [truncated]
Metabase, an open-source business intelligence tool, had a critical vulnerability (CVE-2026-59826, CVSS score of 9.1) in versions from 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2. The issue allowed authenticated administrators to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server due to a lack of validation of unsafe H2 connection properties. This vu [truncated]
CVE-2021-41277 is a Metabase GeoJSON API local file inclusion vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-11-12. The KEV listing means CISA has determined the issue has been exploited in the wild, so exposed Metabase deployments should be treated as a priority remediation item. The supplied records do not include a CVSS score, so prioritization here is driven by kn [truncated]