CVE-2026-59827
metabase: Deserialization of Untrusted Data (CVE-2026-59827)
Affected
- metabase/metabase
between 0.58.0..0.58.15 - metabase/metabase
between 0.59.0..0.59.12 - metabase/metabase
between 0.60.0..0.60.6.3 - metabase/metabase
between 0.61.0..0.61.1.4 - metabase/metabase
between 1.58.0..1.58.15 - metabase/metabase
between 1.59.0..1.59.12 - metabase/metabase
between 1.60.0..1.60.6.3 - metabase/metabase
between 1.61.0..1.61.1.4
Description
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
0.58.0 – 0.58.150.59.0 – 0.59.120.60.0 – 0.60.6.30.61.0 – 0.61.1.41.58.0 – 1.58.151.59.0 – 1.59.121.60.0 – 1.60.6.31.61.0 – 1.61.1.4Metrics
Show all metrics
Weakness classes (CWE)
CWE-502Base
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
cwe.mitre.org →
References & sources
- https://github.com/metabase/metabase/security/advisories/GHSA-w95f-x9v9-wv36x_refsource_CONFIRM
- https://github.com/metabase/metabase/commit/00f42511fe3bc4385652a2e96862ee6fd7d42cf8x_refsource_MISC
- https://github.com/metabase/metabase/releases/tag/v0.58.15x_refsource_MISC
- https://github.com/metabase/metabase/releases/tag/v0.59.12x_refsource_MISC
- https://github.com/metabase/metabase/releases/tag/v0.60.6.3x_refsource_MISC
- https://github.com/metabase/metabase/releases/tag/v0.61.1.4x_refsource_MISC
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-07-09 18:16 UTC· security-advisories@github.com
- Affected: metabase
- Description: Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.
- CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-502