Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-50148: Metabase: Malicious Files Can Run on Server via Snowflake Connection

CVE-2026-50148 CVE-2026-50148
Summary

An attacker can exploit a flaw in the Snowflake database connection to write malicious files on the Metabase server. This can lead to unauthorized code execution, potentially compromising the server. Metabase users should update to the latest fixed versions to prevent this risk.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
metabase metabase >= 1.54.0, < 1.54.24
Original title
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to ...
Original description
Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake connection to an attacker-controlled server, because a flaw in the Snowflake JDBC driver can write arbitrary files anywhere on the Metabase host, including replacing one of Metabase's own database driver files that later executes inside the Metabase process. This issue is fixed in versions 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4.
mitre CVSS3.1 10.0
Vulnerability type
CWE-73
Published: 15 Jul 2026 · Updated: 20 Jul 2026 · First seen: 15 Jul 2026