{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ametabasemetabase/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*","cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:*","cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-59827"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Metabase (0.58.0 - 0.58.14, 0.59.0 - 0.59.11, 0.60.0 - 0.60.6.2, 0.61.0 - 0.61.1.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Metabase"],"content_html":"\u003cp\u003eMetabase versions 0.58.0 through 0.61.1.4 are affected by a high-severity vulnerability (CVE-2026-59827) that allows authenticated attackers to achieve remote code execution (RCE). The vulnerability stems from insecure deserialization of Java objects within the H2 database engine, which Metabase uses for its internal data storage, including the default sample database.\u003c/p\u003e\n\u003cp\u003eWhen an attacker with sufficient privileges to execute native SQL queries interacts with an H2 database instance, they can leverage the 'OTHER' data type to pass arbitrary serialized Java objects to the application. Because the application fails to validate these objects, they are deserialized upon retrieval, leading to arbitrary code execution with the permissions of the Metabase process. This vulnerability is particularly dangerous for instances where the sample H2 database remains active and accessible to authenticated users. Defenders should prioritize patching to the versions listed in the vendor advisory.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker authenticates to the target Metabase instance with valid user credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the query interface and identifies an accessible H2 database connection.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious serialized Java object payload using external tooling.\u003c/li\u003e\n\u003cli\u003eThe attacker executes a native SQL query via the Metabase '/api/dataset' endpoint containing the payload cast to the H2 'OTHER' data type.\u003c/li\u003e\n\u003cli\u003eThe Metabase application processes the query and retrieves the data from the H2 database.\u003c/li\u003e\n\u003cli\u003eThe application performs insecure deserialization of the object returned in the query result column.\u003c/li\u003e\n\u003cli\u003eThe Java deserialization process triggers the execution of arbitrary system commands on the underlying server host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to execute arbitrary OS commands on the host running the Metabase application. This can lead to complete server compromise, including data exfiltration, lateral movement within the environment, and persistence establishment. The vulnerability affects a broad range of recent Metabase versions across various deployment environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all Metabase installations to versions that address CVE-2026-59827 as documented in the GitHub security advisory GHSA-w95f-x9v9-wv36. If immediate patching is not possible, disable the sample H2 database and restrict 'native query' permissions for all non-administrative users.\u003c/p\u003e\n\u003ch2 id=\"detection-engineering\"\u003eDetection Engineering\u003c/h2\u003e\n\u003cp\u003eDeploy monitoring for the following patterns in web server access logs to identify exploitation attempts:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eEnable web server logging for the '/api/dataset' endpoint to capture POST requests containing SQL queries.\u003c/li\u003e\n\u003cli\u003eMonitor for native SQL queries involving the CAST function directed at H2-type databases that include suspicious hex strings or references to deserialization gadgets.\u003c/li\u003e\n\u003cli\u003eAudit for unauthorized access to the '/api/dataset' endpoint by users without explicit database query permissions.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-03T13:53:34Z","date_published":"2026-09-03T13:53:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-metabase-rce/","summary":"Metabase instances configured with H2 databases are vulnerable to authenticated remote code execution via insecure Java deserialization triggered through native SQL queries, identified as CVE-2026-59827.","title":"Authenticated Remote Code Execution in Metabase via H2 Deserialization","url":"https://feed.craftedsignal.io/briefs/2026-09-metabase-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}