CVE-2026-59826
metabase: Improper Control of Generation of Code ('Code Injection') (CVE-2026-59826)
Affected
- metabase/metabase
between 1.55.0..1.58.15.1 - metabase/metabase
between 1.59.0..1.59.12 - metabase/metabase
between 1.60.0..1.60.6.3 - metabase/metabase
between 1.61.0..1.61.2
Description
Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
1.55.0 – 1.58.15.11.59.0 – 1.59.121.60.0 – 1.60.6.31.61.0 – 1.61.2Metrics
Show all metrics
Weakness classes (CWE)
CWE-94Base
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
cwe.mitre.org →
References & sources
- https://github.com/metabase/metabase/security/advisories/GHSA-8wx2-rxp2-4x35x_refsource_CONFIRM
- https://github.com/metabase/metabase/commit/74032e5e0a5a70dc45a6a744d37b9ba24eee8d01x_refsource_MISC
- https://github.com/metabase/metabase/releases/tag/v0.58.15.1x_refsource_MISC
- https://github.com/metabase/metabase/releases/tag/v0.59.12x_refsource_MISC
- https://github.com/metabase/metabase/releases/tag/v0.60.6.3x_refsource_MISC
- https://github.com/metabase/metabase/releases/tag/v0.61.2x_refsource_MISC
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-07-30 14:32 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* versions from (including) 1.59.0 up to (excluding) 1.59.12 *cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* versions from (including) 1.60.0 up to (excluding) 1.60.6.3 *cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* versions from (including) 1.55.0 up to (excluding) 1.58.15.1 *cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* versions from (including) 1.61.0 up to (excluding) 1.61.2
- Reference Type: GitHub, Inc.: https://github.com/metabase/metabase/commit/74032e5e0a5a70dc45a6a744d37b9ba24eee8d01 Types: Patch
- Reference Type: GitHub, Inc.: https://github.com/metabase/metabase/releases/tag/v0.58.15.1 Types: Product
- Reference Type: GitHub, Inc.: https://github.com/metabase/metabase/releases/tag/v0.59.12 Types: Product, Release Notes
- New CVE Received2026-07-09 18:16 UTC· security-advisories@github.com
- Affected: metabase
- Description: Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.
- CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-94