Metabase disclosed CVE-2026-59827, a critical unsafe deserialization vulnerability that can lead to remote code execution on the Metabase server when instances use an H2 database connection, including the default sample database. The flaw allows an authenticated user with permission to run native H2 queries to return query result columns of type OTHER, causing Metabase to deserialize arbitrary Java objects. The issue carries a CVSS 9.9 rating and affects versions 1.58.0 through before 1.58.15, 1.59.0 through before 1.59.12, 1.60.0 through before 1.60.6.3, and 1.61.0 through before 1.61.1.4.
A related Metabase code change in the H2 database driver shows the remediation path: the application now checks JDBC result metadata and rejects columns typed as JAVA_OBJECT instead of attempting to parse them. That defensive change blocks unsafe handling of serialized Java objects in H2 query results and aligns with the vendor fixes released in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-59827 was publicly disclosed as a critical Metabase unsafe deserialization vulnerability with a CVSS 9.9 score. The advisory states it affects versions 1.58.0 through before 1.58.15, 1.59.0 through before 1.59.12, 1.60.0 through before 1.60.6.3, and 1.61.0 through before 1.61.1.4.
Metabase fixed the unsafe deserialization vulnerability CVE-2026-59827 in versions 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4. The flaw affected instances using an H2 database connection and could allow authenticated code execution via native H2 queries returning OTHER-type columns.
A Metabase code change added a defensive check in the H2 database driver to throw an exception when a JDBC result-set column has type JAVA_OBJECT, preventing unsafe parsing of such values.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.