CVE-2026-59826
Metabase versions 1.55.0 through 1.61.2 contain a flaw that lets an authenticated administrator register a specially crafted H2 database connection and run arbitrary Java code on the server. This can give the attacker full control over the Metabase instance and the underlying host. The vulnerability is rated critical with a CVSS score of 9.1.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Metabase 1.55.0 to 1.61.2, inclusive. Users who have administrative access to a Metabase installation are at risk.
Real-world impact
An attacker who can log in as an administrator could run any Java code on the Metabase server, potentially taking over the host, stealing data, or installing malware.
Why this severity
The CVSS score of 9.1 reflects that the flaw allows remote attackers to execute arbitrary code with high privileges, no user interaction is needed, and it compromises confidentiality, integrity, and availability of the system.
What to do about it
- 011. Identify the current Metabase version.
- 022. Download a patched version (1.58.15.1, 1.59.12, 1.60.6.3, or 1.61.2).
- 033. Upgrade Metabase to the patched version.
- 044. Restart the Metabase service.
NVD-referenced vendor advisory
Timeline
- Jul 9, 2026 · 25d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 4d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 4d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/metabase/metabase/commit/74…patch
- github.com/metabase/metabase/releases/…product
- github.com/metabase/metabase/releases/…productrelease notes
- github.com/metabase/metabase/releases/…product
- github.com/metabase/metabase/releases/…productrelease notes
- github.com/metabase/metabase/security/…vendor advisory