CVE-2026-50148
NixOS 脆弱性の分析と軽減

概要

CVE-2026-50148 is a critical Remote Code Execution (RCE) vulnerability in Metabase, an open-source business intelligence and embedded analytics platform, arising from an arbitrary file write flaw in the Snowflake JDBC driver. It affects Metabase versions from 1.54.0 through multiple release branches, specifically before 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4. The vulnerability was published on July 15, 2026, with the GitHub Security Advisory (GHSA-r6x2-rchx-q9g9) originally published May 28, 2026. It carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory, Feedly).

技術的な詳細

The root cause is an external control of file name or path flaw (CWE-73) in the Snowflake JDBC driver bundled with Metabase, which allows an attacker-controlled Snowflake server to write arbitrary files to any location on the Metabase host filesystem. An attacker with permission to add or edit a database connection configures a Snowflake connection pointing to a server they control; the malicious server exploits the JDBC driver flaw to overwrite one of Metabase's own database driver files on disk. The next time Metabase loads the replaced driver file, the attacker's code executes within the Metabase process context. The fix addresses this by bundling Metabase's first-party drivers directly into the main application file, preventing them from being replaced on disk (GitHub Advisory).

影響

Successful exploitation results in full remote code execution on the Metabase server, with complete compromise of confidentiality, integrity, and availability. An attacker can read sensitive data (including database credentials, business intelligence data, and internal configurations), modify or destroy data, and disrupt service availability. Because the attacker's code runs inside the Metabase process, there is significant potential for lateral movement to connected databases and internal network resources (GitHub Advisory, Feedly).

エクスプロイト可能性

As of the time of publication, there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.0044 (0.44%), indicating a currently low probability of exploitation in the near term. The vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction once an attacker has the required database connection permissions. No threat actor attribution or CISA KEV catalog listing has been reported at this time (Feedly).

エクスプロイテーションのステップ

  1. Gain database connection permissions: Obtain a Metabase account with administrator or equivalent privileges that allow adding or editing database connections (e.g., through credential theft, phishing, or insider access).
  2. Set up a malicious Snowflake server: Deploy an attacker-controlled server that mimics a Snowflake endpoint and is configured to exploit the Snowflake JDBC driver's arbitrary file write vulnerability.
  3. Configure a Snowflake connection in Metabase: In the Metabase admin panel, add a new database connection of type Snowflake, pointing the connection URL/host to the attacker-controlled server.
  4. Trigger the JDBC driver connection: Initiate a connection test or save the connection, causing Metabase to use the Snowflake JDBC driver to connect to the attacker's server.
  5. Exploit arbitrary file write: The attacker-controlled server instructs the Snowflake JDBC driver to write a malicious payload file, overwriting one of Metabase's database driver files on the host filesystem.
  6. Achieve code execution: Wait for or trigger Metabase to reload the replaced driver file; the attacker's code executes inside the Metabase process, enabling reverse shell, data exfiltration, or further lateral movement (GitHub Advisory).

妥協の兆候

  • Network: Outbound connections from the Metabase server to unexpected or external Snowflake-like endpoints (non-standard Snowflake hostnames or IPs); unusual JDBC connection attempts to external hosts not matching known Snowflake infrastructure.
  • File System: Unexpected modification timestamps on Metabase driver files (e.g., files in the Metabase drivers directory); presence of new or altered .jar or driver files in Metabase installation directories; file integrity monitoring alerts on Metabase application directories.
  • Logs: Metabase application logs showing new or edited Snowflake database connection configurations pointing to external/unknown hosts; errors or unusual activity during driver loading in Metabase logs.
  • Process: Unexpected child processes spawned by the Metabase Java process (e.g., shells, curl, wget, or scripting interpreters); unusual outbound network connections initiated by the Metabase process after a driver reload event (GitHub Advisory, Feedly).

軽減策と回避策

Metabase has released patched versions that bundle first-party drivers into the main application file, preventing on-disk replacement: 1.54.24, 0.54.24, 1.55.24, 0.55.24, 1.56.25, 0.56.25, 1.57.19, 0.57.19, 1.58.14, 0.58.14, 1.59.10, 0.59.10, 1.60.4, and 0.60.4. Organizations should upgrade to the appropriate patched version immediately. As interim mitigations, restrict the ability to add or edit database connections to only highly trusted administrators, monitor for suspicious file write operations in Metabase directories, implement file integrity monitoring, and consider network-level controls to prevent Metabase from connecting to unauthorized external hosts (GitHub Advisory, Feedly).

コミュニティの反応

The vulnerability was reported to Metabase by Hacktron AI and received attention on social media shortly after disclosure, including a post on Mastodon via The Hacker Wire (Feedly). The critical CVSS score of 10.0 drew broad coverage from vulnerability tracking platforms including VulDB, Vulners, and CVEFeed. No major vendor statements beyond the official Metabase GitHub Security Advisory have been identified at this time.

関連情報


ソースこのレポートは AI を使用して生成されました

関連 NixOS 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
いいえはいAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
いいえはいAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
いいえはいAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
いいえはいAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
いいえはいAug 06, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者