CVE-2026-27464 Details
Description
Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase instance, including database access credentials. During testing, it was confirmed that a low-privileged user can extract sensitive information including database credentials, into the email body via template evaluation. This issue has been fixed in versions 0.57.13 and 0.58.7. To workaround this issue, users can disable notifications in their Metabase instance to disallow access to the vulnerable endpoints.
A vulnerability exists in Metabase, an open-source data analytics platform, in versions prior to 0.57.13 and in the 0.58.x series up to 0.58.6. Authenticated users can exploit this vulnerability to access sensitive information from the Metabase instance, including database access credentials. This is achieved by sending a specific template through the notifications endpoint, which is then evaluated server-side. The rendered output, containing the extracted credentials, is included in the email body. This issue has been addressed in Metabase versions 0.57.13 and 0.58.7.
Users can upgrade to Metabase versions 0.57.13 or 0.58.7. For Metabase Enterprise users, versions 1.57.13 and 1.58.7 are available. Instructions for downloading the JAR files or using the Docker images for these versions can be found in the Metabase release notes. As an additional step, users can temporarily disable notifications in their Metabase instance to prevent access to the vulnerable endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/metabase/metabase/releases/tag/v0.57.13 | [email protected] | ProductRelease Notes |
| https://github.com/metabase/metabase/releases/tag/v0.58.7 | [email protected] | ProductRelease Notes |
| https://github.com/metabase/metabase/security/advisories/GHSA-vcj8-rcm8-gfj9 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| metabase metabase | < 0.57.13 < 1.57.13 >= 0.58.0, < 0.58.7 >= 1.58.0, < 1.58.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 2, 2026 | Initial Analysis | [email protected] |
| Feb 21, 2026 | New CVE Received | [email protected] |