CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-59827

Critical · CVSS 9.9

Metabase — Java deserialization RCE via H2 native query OTHER column type

CVSS
9.9
nvd
EPSS
0.45%
36th pct
KEV
No
Class
oss containerizable
CWE-502

Description

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.

Search profile — drives PoC discovery

Symbols H2native queryOTHERdeserializeCWE-502sample databaseJava objectsresult columns00f42511fe3bc4385652a2e96862ee6fd7d42cf8
Keywords CVE-2026-59827MetabaseH2 databasedeserializationRCEnative queryOTHER typeauthenticated RCEMetabase exploitMetabase PoCCWE-502 MetabaseH2 deserialization Metabase
Versions: < 1.58.15, < 1.59.12, < 1.60.6.3, < 1.61.1.4

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-13T18:00:21.000Z · profiled 2026-07-13T18:30:21.000Z