CVE-2026-50148 Details
Description
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in versions 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4.
A remote code execution vulnerability has been identified in Metabase versions 1.54.0 prior to 1.54.24, 1.55.0 prior to 1.55.24, 1.56.0 prior to 1.56.25, 1.57.0 prior to 1.57.19, 1.58.0 prior to 1.58.14, 1.59.0 prior to 1.59.10, and 1.60.0 prior to 1.60.4. This vulnerability allows a Metabase user with permission to add or edit database connections to execute arbitrary code on the Metabase server. The issue arises from a flaw in the Snowflake JDBC driver, which can write files to any location on the Metabase host. This includes the ability to overwrite Metabase's own database driver files, which are subsequently executed within the Metabase process.
Users can upgrade to Metabase versions 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, or 1.60.4 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/metabase/metabase/security/advisories/GHSA-r6x2-rchx-q9g9 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-73 | External Control of File Name or Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| metabase metabase | >= 1.54.0, < 1.54.24 >= 1.55.0, < 1.55.24 >= 1.56.0, < 1.56.25 >= 1.57.0, < 1.57.19 >= 1.58.0, < 1.58.14 >= 1.59.0, < 1.59.10 >= 1.60.0, < 1.60.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |