
PEACH
Un cadre d’isolation des locataires
CVE-2026-50148 is a critical Remote Code Execution (RCE) vulnerability in Metabase, an open-source business intelligence and embedded analytics platform, arising from an arbitrary file write flaw in the Snowflake JDBC driver. It affects Metabase versions from 1.54.0 through multiple release branches, specifically before 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4. The vulnerability was published on July 15, 2026, with the GitHub Security Advisory (GHSA-r6x2-rchx-q9g9) originally published May 28, 2026. It carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory, Feedly).
The root cause is an external control of file name or path flaw (CWE-73) in the Snowflake JDBC driver bundled with Metabase, which allows an attacker-controlled Snowflake server to write arbitrary files to any location on the Metabase host filesystem. An attacker with permission to add or edit a database connection configures a Snowflake connection pointing to a server they control; the malicious server exploits the JDBC driver flaw to overwrite one of Metabase's own database driver files on disk. The next time Metabase loads the replaced driver file, the attacker's code executes within the Metabase process context. The fix addresses this by bundling Metabase's first-party drivers directly into the main application file, preventing them from being replaced on disk (GitHub Advisory).
Successful exploitation results in full remote code execution on the Metabase server, with complete compromise of confidentiality, integrity, and availability. An attacker can read sensitive data (including database credentials, business intelligence data, and internal configurations), modify or destroy data, and disrupt service availability. Because the attacker's code runs inside the Metabase process, there is significant potential for lateral movement to connected databases and internal network resources (GitHub Advisory, Feedly).
As of the time of publication, there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.0044 (0.44%), indicating a currently low probability of exploitation in the near term. The vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction once an attacker has the required database connection permissions. No threat actor attribution or CISA KEV catalog listing has been reported at this time (Feedly).
.jar or driver files in Metabase installation directories; file integrity monitoring alerts on Metabase application directories.Metabase has released patched versions that bundle first-party drivers into the main application file, preventing on-disk replacement: 1.54.24, 0.54.24, 1.55.24, 0.55.24, 1.56.25, 0.56.25, 1.57.19, 0.57.19, 1.58.14, 0.58.14, 1.59.10, 0.59.10, 1.60.4, and 0.60.4. Organizations should upgrade to the appropriate patched version immediately. As interim mitigations, restrict the ability to add or edit database connections to only highly trusted administrators, monitor for suspicious file write operations in Metabase directories, implement file integrity monitoring, and consider network-level controls to prevent Metabase from connecting to unauthorized external hosts (GitHub Advisory, Feedly).
The vulnerability was reported to Metabase by Hacktron AI and received attention on social media shortly after disclosure, including a post on Mastodon via The Hacker Wire (Feedly). The critical CVSS score of 10.0 drew broad coverage from vulnerability tracking platforms including VulDB, Vulners, and CVEFeed. No major vendor statements beyond the official Metabase GitHub Security Advisory have been identified at this time.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."