PT-2026-60209 · Metabase+1 · Metabase
CVE-2026-50147
·
Published
2026-07-15
·
Updated
2026-07-15
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Metabase versions 1.57.0 through 1.57.19.0
Metabase versions 1.58.0 through 1.58.14.0
Metabase versions 1.59.0 through 1.59.9
Metabase versions 1.60.0 through 1.60.3
Description
An attacker with permissions to configure a database connection can read arbitrary files from the server filesystem. By adding unsafe JDBC (Java Database Connectivity) parameters to a MySQL or MariaDB connection, the driver reads files from the host and exposes the content via database queries or validation error messages.
Recommendations
Update to version 1.57.19.1
Update to version 1.58.14.1
Update to version 1.59.10
Update to version 1.60.4
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metabase