CVE-2026-59827

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
09/07/2026
Last modified:
13/07/2026

Description

Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:* 0.58.0 (including) 0.58.15 (excluding)
cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:* 0.59.0 (including) 0.59.12 (excluding)
cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:* 0.60.0 (including) 0.60.6.3 (excluding)
cpe:2.3:a:metabase:metabase:*:*:*:*:-:*:*:* 0.61.0 (including) 0.61.1.4 (excluding)
cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* 1.58.0 (including) 1.58.15 (excluding)
cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* 1.59.0 (including) 1.59.12 (excluding)
cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* 1.60.0 (including) 1.60.6.3 (excluding)
cpe:2.3:a:metabase:metabase:*:*:*:*:enterprise:*:*:* 1.61.0 (including) 1.61.1.4 (excluding)