Event Dime
Does metabase free affected by CVE-2026-59826
- When:
- July 20, 2026 · 5:13 AM
- Where:
- Metabase Discussion
- Source:
- Metabase Discussion
The version numbers in the advisory are for paid versions, so it doesn’t affect OSS unless its an oversight. Its possible the database registration flow mentioned only exists in paid. OSS does have H2 and previous advisories have applied to it, mainly the one where you can send interpreted commands through the connection string. At that time it was recommended to discontinue use of H2. GitHub Remote code execution via user-supplied H2 connection strings # What is the Vulnerability? The core issu