PT-2026-60209 · Metabase+1 · Metabase

CVE-2026-50147

·

Published

2026-07-15

·

Updated

2026-07-15

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Metabase versions 1.57.0 through 1.57.19.0 Metabase versions 1.58.0 through 1.58.14.0 Metabase versions 1.59.0 through 1.59.9 Metabase versions 1.60.0 through 1.60.3
Description An attacker with permissions to configure a database connection can read arbitrary files from the server filesystem. By adding unsafe JDBC (Java Database Connectivity) parameters to a MySQL or MariaDB connection, the driver reads files from the host and exposes the content via database queries or validation error messages.
Recommendations Update to version 1.57.19.1 Update to version 1.58.14.1 Update to version 1.59.10 Update to version 1.60.4

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50147

Affected Products

Metabase