CVE-2026-59827 Details
Description
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execute code on the Metabase server. This issue is fixed in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.
A vulnerability exists in Metabase versions prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, specifically in instances using an H2 database connection, including the default sample database. The issue arises because Metabase deserializes arbitrary Java objects from H2 native query result columns of type 'OTHER' without proper validation. This flaw enables an authenticated user who can execute native H2 queries to run code on the Metabase server.
Users can upgrade to Metabase versions 1.58.15, 1.59.12, 1.60.6.3, or 1.61.1.4 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| metabase metabase | >= 0.58.0, < 0.58.15 >= 0.59.0, < 0.59.12 >= 0.60.0, < 0.60.6.3 >= 0.61.0, < 0.61.1.4 >= 1.58.0, < 1.58.15 >= 1.59.0, < 1.59.12 >= 1.60.0, < 1.60.6.3 >= 1.61.0, < 1.61.1.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | Initial Analysis | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |