PT-2026-66572 · Somta+1 · Juggle

·

CVE-2026-67208

·

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Juggle versions prior to 1.6.0
Description Unauthenticated remote attackers can execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected '/h2-console' endpoint and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute commands, which results in root-level code execution when using the stock Docker image.
Recommendations Update to version 1.6.0 or later. Restrict access to the '/h2-console' endpoint. Change the default shipped credentials for the H2 database web console.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67208

Affected Products

Juggle