CVE-2026-50147: Metabase: Arbitrary File Read via MySQL Connection Property Injection
Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metabase server's filesystem by adding unsafe JDBC parameters to a MySQL or MariaDB connection, causing the driver to read files from the Metabase host and expose the contents through queries against the connected database or through validation error messages. This issue is fixed in versions 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Metabaseto a version that resolves this vulnerability.Fixed in 1.57.19.1 - Upgrade
Upgrade
Metabaseto a version that resolves this vulnerability.Fixed in 1.58.14.1 - Upgrade
Upgrade
Metabaseto a version that resolves this vulnerability.Fixed in 1.59.10 - Upgrade
Upgrade
Metabaseto a version that resolves this vulnerability.Fixed in 1.60.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50147?
The severity of CVE-2026-50147 is rated high, with a score of 7.6.
How do I fix CVE-2026-50147?
To fix CVE-2026-50147, upgrade Metabase to version 1.57.20 or higher, or to 1.58.15 or higher, or to 1.59.11 or higher, or to 1.60.5 or higher.
What type of vulnerability is CVE-2026-50147?
CVE-2026-50147 is an arbitrary file read vulnerability caused by unsafe JDBC parameter injection.
Who is affected by CVE-2026-50147?
Users of Metabase versions 1.57.0 through 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4 are affected by CVE-2026-50147.
What can an attacker do with CVE-2026-50147?
An attacker can read arbitrary files from the Metabase server's filesystem if they can configure a database connection.