CVE-2026-59827

metabase: Deserialization of Untrusted Data (CVE-2026-59827)

criticalPoCEPSS 3.8%

Affected

  • metabase/metabase between 0.58.0..0.58.15
  • metabase/metabase between 0.59.0..0.59.12
  • metabase/metabase between 0.60.0..0.60.6.3
  • metabase/metabase between 0.61.0..0.61.1.4
  • metabase/metabase between 1.58.0..1.58.15
  • metabase/metabase between 1.59.0..1.59.12
  • metabase/metabase between 1.60.0..1.60.6.3
  • metabase/metabase between 1.61.0..1.61.1.4

Description

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

metabasemetabase
0.58.0 – 0.58.150.59.0 – 0.59.120.60.0 – 0.60.6.30.61.0 – 0.61.1.41.58.0 – 1.58.151.59.0 – 1.59.121.60.0 – 1.60.6.31.61.0 – 1.61.1.4

Metrics

9.9
Source: cna-v3
89.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
critical
PoC (publicly reported)
3.8 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-07-09 18:16 UTC
CWE-502

Weakness classes (CWE)

  • CWE-502Base

    Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. New CVE Received2026-07-09 18:16 UTC· security-advisories@github.com
    • Affected: metabase
    • Description: Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-502

Linked advisories