CVE-2026-27464: Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCE
Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase instance, including database access credentials. During testing, it was confirmed that a low-privileged user can extract sensitive information including database credentials, into the email body via template evaluation. This issue has been fixed in versions 0.57.13 and 0.58.7. To workaround this issue, users can disable notifications in their Metabase instance to disallow access to the vulnerable endpoints.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27464?
CVE-2026-27464 is a critical vulnerability that can lead to remote code execution.
How do I fix CVE-2026-27464?
To remediate CVE-2026-27464, upgrade Metabase to version 0.57.13 or 0.58.7 or later.
Who is affected by CVE-2026-27464?
CVE-2026-27464 affects Metabase users on versions prior to 0.57.13 and 0.58.0 through 0.58.6.
What kind of attack is CVE-2026-27464?
CVE-2026-27464 involves server-side template injection that could lead to unauthorized data access or execution of malicious code.
Can authenticated users exploit CVE-2026-27464?
Yes, authenticated users can exploit CVE-2026-27464 to retrieve sensitive information from the Metabase instance.