Description
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in versions 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4.
Published: 2026-07-15
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Metabase is an open‑source business intelligence and embedded analytics tool. The vulnerability, rooted in the Snowflake JDBC driver, allows an arbitrary file write to any location on the host when a Metabase user with permission to create or edit a Snowflake database connection points the tool to an attacker‑controlled server. The flaw is present in Metabase releases from 1.54.0 up through 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4. An attacker can overwrite Metabase’s own JDBC driver or other files, causing the Metabase process to execute malicious code, leading to remote code execution that compromises confidentiality, integrity, and availability. This is a classic CWE‑73 arbitrary file write weakness.

Affected Systems

The affected product is the Metabase open‑source business intelligence and embedded analytics tool. Vulnerable releases include any Metabase 1.54 series version older than 1.54.24, any 1.55 series older than 1.55.24, any 1.56 series older than 1.56.25, any 1.57 series older than 1.57.19, any 1.58 series older than 1.58.14, any 1.59 series older than 1.59.10, or any 1.60 series older than 1.60.4; any installation running such a version that allows users to create or edit Snowflake database connections is at risk.

Risk and Exploitability

The CVSS score of 10 signals a critical severity, while the EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation as of the latest assessment. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need permissions typically granted only to privileged administrators or power users to create or edit Snowflake database connections; the likely attack vector is via the Metabase web interface that allows such configuration. If such privileges exist, the flaw can be abused to write arbitrary files and trigger remote code execution, exemplifying a CWE‑73 weakness.

Generated by OpenCVE AI on July 31, 2026 at 03:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Metabase to any version newer than 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, or 1.60.4, which contain the fix for the JavaDB driver flaw.
  • Restrict the creation or editing of Snowflake database connections to users with explicit administrative privileges, eliminating the opportunity for unauthorized users to configure connections that could be exploited.
  • If immediate upgrade is not feasible, temporarily disable Snowflake database connections until the Metabase instance is patched or the JDBC driver flaw is mitigated.

Generated by OpenCVE AI on July 31, 2026 at 03:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Metabase
Metabase metabase
Vendors & Products Metabase
Metabase metabase

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in versions 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4.
Title Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Metabase Metabase
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-20T14:55:07.812Z

Reserved: 2026-06-03T18:49:32.276Z

Link: CVE-2026-50148

cve-icon Vulnrichment

Updated: 2026-07-20T14:55:01.896Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:30:18Z

Weaknesses
  • CWE-73

    External Control of File Name or Path