CVE-2026-50148
NixOS Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-50148 is a critical Remote Code Execution (RCE) vulnerability in Metabase, an open-source business intelligence and embedded analytics platform, arising from an arbitrary file write flaw in the Snowflake JDBC driver. It affects Metabase versions from 1.54.0 through multiple release branches, specifically before 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4. The vulnerability was published on July 15, 2026, with the GitHub Security Advisory (GHSA-r6x2-rchx-q9g9) originally published May 28, 2026. It carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory, Feedly).

Détails techniques

The root cause is an external control of file name or path flaw (CWE-73) in the Snowflake JDBC driver bundled with Metabase, which allows an attacker-controlled Snowflake server to write arbitrary files to any location on the Metabase host filesystem. An attacker with permission to add or edit a database connection configures a Snowflake connection pointing to a server they control; the malicious server exploits the JDBC driver flaw to overwrite one of Metabase's own database driver files on disk. The next time Metabase loads the replaced driver file, the attacker's code executes within the Metabase process context. The fix addresses this by bundling Metabase's first-party drivers directly into the main application file, preventing them from being replaced on disk (GitHub Advisory).

Impact

Successful exploitation results in full remote code execution on the Metabase server, with complete compromise of confidentiality, integrity, and availability. An attacker can read sensitive data (including database credentials, business intelligence data, and internal configurations), modify or destroy data, and disrupt service availability. Because the attacker's code runs inside the Metabase process, there is significant potential for lateral movement to connected databases and internal network resources (GitHub Advisory, Feedly).

Exploitabilité

As of the time of publication, there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.0044 (0.44%), indicating a currently low probability of exploitation in the near term. The vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction once an attacker has the required database connection permissions. No threat actor attribution or CISA KEV catalog listing has been reported at this time (Feedly).

Étapes d’exploitation

  1. Gain database connection permissions: Obtain a Metabase account with administrator or equivalent privileges that allow adding or editing database connections (e.g., through credential theft, phishing, or insider access).
  2. Set up a malicious Snowflake server: Deploy an attacker-controlled server that mimics a Snowflake endpoint and is configured to exploit the Snowflake JDBC driver's arbitrary file write vulnerability.
  3. Configure a Snowflake connection in Metabase: In the Metabase admin panel, add a new database connection of type Snowflake, pointing the connection URL/host to the attacker-controlled server.
  4. Trigger the JDBC driver connection: Initiate a connection test or save the connection, causing Metabase to use the Snowflake JDBC driver to connect to the attacker's server.
  5. Exploit arbitrary file write: The attacker-controlled server instructs the Snowflake JDBC driver to write a malicious payload file, overwriting one of Metabase's database driver files on the host filesystem.
  6. Achieve code execution: Wait for or trigger Metabase to reload the replaced driver file; the attacker's code executes inside the Metabase process, enabling reverse shell, data exfiltration, or further lateral movement (GitHub Advisory).

Indicateurs de compromis

  • Network: Outbound connections from the Metabase server to unexpected or external Snowflake-like endpoints (non-standard Snowflake hostnames or IPs); unusual JDBC connection attempts to external hosts not matching known Snowflake infrastructure.
  • File System: Unexpected modification timestamps on Metabase driver files (e.g., files in the Metabase drivers directory); presence of new or altered .jar or driver files in Metabase installation directories; file integrity monitoring alerts on Metabase application directories.
  • Logs: Metabase application logs showing new or edited Snowflake database connection configurations pointing to external/unknown hosts; errors or unusual activity during driver loading in Metabase logs.
  • Process: Unexpected child processes spawned by the Metabase Java process (e.g., shells, curl, wget, or scripting interpreters); unusual outbound network connections initiated by the Metabase process after a driver reload event (GitHub Advisory, Feedly).

Atténuation et solutions de contournement

Metabase has released patched versions that bundle first-party drivers into the main application file, preventing on-disk replacement: 1.54.24, 0.54.24, 1.55.24, 0.55.24, 1.56.25, 0.56.25, 1.57.19, 0.57.19, 1.58.14, 0.58.14, 1.59.10, 0.59.10, 1.60.4, and 0.60.4. Organizations should upgrade to the appropriate patched version immediately. As interim mitigations, restrict the ability to add or edit database connections to only highly trusted administrators, monitor for suspicious file write operations in Metabase directories, implement file integrity monitoring, and consider network-level controls to prevent Metabase from connecting to unauthorized external hosts (GitHub Advisory, Feedly).

Réactions de la communauté

The vulnerability was reported to Metabase by Hacktron AI and received attention on social media shortly after disclosure, including a post on Mastodon via The Hacker Wire (Feedly). The critical CVSS score of 10.0 drew broad coverage from vulnerability tracking platforms including VulDB, Vulners, and CVEFeed. No major vendor statements beyond the official Metabase GitHub Security Advisory have been identified at this time.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté NixOS Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NonOuiAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NonOuiAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NonOuiAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NonOuiAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NonOuiAug 06, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités