CPE
Metabase instances configured with H2 databases are vulnerable to authenticated remote code execution via insecure Java deserialization triggered through native SQL queries, identified as CVE-2026-59827.