
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50148 is a critical Remote Code Execution (RCE) vulnerability in Metabase, an open-source business intelligence and embedded analytics platform, arising from an arbitrary file write flaw in the Snowflake JDBC driver. It affects Metabase versions from 1.54.0 through multiple release branches, specifically before 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4. The vulnerability was published on July 15, 2026, with the GitHub Security Advisory (GHSA-r6x2-rchx-q9g9) originally published May 28, 2026. It carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory, Feedly).
The root cause is an external control of file name or path flaw (CWE-73) in the Snowflake JDBC driver bundled with Metabase, which allows an attacker-controlled Snowflake server to write arbitrary files to any location on the Metabase host filesystem. An attacker with permission to add or edit a database connection configures a Snowflake connection pointing to a server they control; the malicious server exploits the JDBC driver flaw to overwrite one of Metabase's own database driver files on disk. The next time Metabase loads the replaced driver file, the attacker's code executes within the Metabase process context. The fix addresses this by bundling Metabase's first-party drivers directly into the main application file, preventing them from being replaced on disk (GitHub Advisory).
Successful exploitation results in full remote code execution on the Metabase server, with complete compromise of confidentiality, integrity, and availability. An attacker can read sensitive data (including database credentials, business intelligence data, and internal configurations), modify or destroy data, and disrupt service availability. Because the attacker's code runs inside the Metabase process, there is significant potential for lateral movement to connected databases and internal network resources (GitHub Advisory, Feedly).
As of the time of publication, there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.0044 (0.44%), indicating a currently low probability of exploitation in the near term. The vulnerability is rated as automatable by NVD SSVC analysis, meaning exploitation could be scripted without manual interaction once an attacker has the required database connection permissions. No threat actor attribution or CISA KEV catalog listing has been reported at this time (Feedly).
.jar or driver files in Metabase installation directories; file integrity monitoring alerts on Metabase application directories.Metabase has released patched versions that bundle first-party drivers into the main application file, preventing on-disk replacement: 1.54.24, 0.54.24, 1.55.24, 0.55.24, 1.56.25, 0.56.25, 1.57.19, 0.57.19, 1.58.14, 0.58.14, 1.59.10, 0.59.10, 1.60.4, and 0.60.4. Organizations should upgrade to the appropriate patched version immediately. As interim mitigations, restrict the ability to add or edit database connections to only highly trusted administrators, monitor for suspicious file write operations in Metabase directories, implement file integrity monitoring, and consider network-level controls to prevent Metabase from connecting to unauthorized external hosts (GitHub Advisory, Feedly).
The vulnerability was reported to Metabase by Hacktron AI and received attention on social media shortly after disclosure, including a post on Mastodon via The Hacker Wire (Feedly). The critical CVSS score of 10.0 drew broad coverage from vulnerability tracking platforms including VulDB, Vulners, and CVEFeed. No major vendor statements beyond the official Metabase GitHub Security Advisory have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."