CVE-2026-50148
Undergoing Analysis Undergoing Analysis - In Progress

Remote Code Execution in Metabase via Snowflake JDBC Driver

Vulnerability report for CVE-2026-50148, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-15

Last updated on: 2026-07-30

Assigner: GitHub, Inc.

Description

Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in versions 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-15
Last Modified
2026-07-30
Generated
2026-08-05
AI Q&A
2026-07-16
EPSS Evaluated
2026-08-03
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
metabase metabase From 1.59.0 (inc) to 1.59.10 (exc)
metabase metabase From 1.60.0 (inc) to 1.60.4 (exc)
metabase metabase From 1.54.0 (inc) to 1.54.24 (exc)
metabase metabase From 1.55.0 (inc) to 1.55.24 (exc)
metabase metabase From 1.56.0 (inc) to 1.56.25 (exc)
metabase metabase From 1.57.0 (inc) to 1.57.19 (exc)
metabase metabase From 1.58.0 (inc) to 1.58.14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Metabase allows a user with permission to edit database connections to execute remote code on the server. The flaw exists in versions between 1.54.0 and 1.60.3 and is exploited via the Snowflake JDBC driver, which can write arbitrary files on the Metabase host. Attackers can replace Metabase's driver files, leading to malicious code execution when the application reloads the driver.

Detection Guidance

Check Metabase versions between 1.54.0 and 1.60.3. Look for unauthorized file writes in Metabase directories, especially driver files. Review database connection logs for suspicious Snowflake JDBC driver modifications.

Impact Analysis

An attacker could gain full control over the Metabase server, leading to unauthorized access, data theft, or system compromise. This includes potential exposure of sensitive data stored in Metabase or connected databases.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR, HIPAA, or other regulations. It may result in unauthorized access to personal or health data, triggering legal penalties, fines, or reputational damage.

Mitigation Strategies

Upgrade Metabase to a patched version (1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, or 1.60.4). Restrict database connection edit permissions to trusted users only. Monitor for unauthorized file changes in Metabase directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50148. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart