CVE-2026-59826

metabase: Improper Control of Generation of Code ('Code Injection') (CVE-2026-59826)

criticalEPSS 1.0%

Affected

  • metabase/metabase between 1.55.0..1.58.15.1
  • metabase/metabase between 1.59.0..1.59.12
  • metabase/metabase between 1.60.0..1.60.6.3
  • metabase/metabase between 1.61.0..1.61.2

Description

Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

metabasemetabase
1.55.0 – 1.58.15.11.59.0 – 1.59.121.60.0 – 1.60.6.31.61.0 – 1.61.2

Metrics

9.1
Source: nvd-v3
62.0 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
1.0 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-07-09 18:16 UTC
CWE-94

Weakness classes (CWE)

  • CWE-94Base

    Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-07-30 14:32 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* versions from (including) 1.59.0 up to (excluding) 1.59.12 *cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* versions from (including) 1.60.0 up to (excluding) 1.60.6.3 *cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* versions from (including) 1.55.0 up to (excluding) 1.58.15.1 *cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* versions from (including) 1.61.0 up to (excluding) 1.61.2
    • Reference Type: GitHub, Inc.: https://github.com/metabase/metabase/commit/74032e5e0a5a70dc45a6a744d37b9ba24eee8d01 Types: Patch
    • Reference Type: GitHub, Inc.: https://github.com/metabase/metabase/releases/tag/v0.58.15.1 Types: Product
    • Reference Type: GitHub, Inc.: https://github.com/metabase/metabase/releases/tag/v0.59.12 Types: Product, Release Notes
  2. New CVE Received2026-07-09 18:16 UTC· security-advisories@github.com
    • Affected: metabase
    • Description: Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in versions 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2.
    • CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-94

Linked advisories