B
今週中
Metabaseの特定のバージョンにおいて、認証済みユーザーがH2データベース接続を利用して任意のJavaオブジェクトをデシリアライズできる脆弱性
📌 一言でいうと
Metabaseの特定のバージョンにおいて、認証済みユーザーがH2データベース接続を利用して任意のJavaオブジェクトをデシリアライズできる脆弱性が発見されました。攻撃者はネイティブクエリを実行することで、サーバー上で任意のOSコマンドを実行できる可能性があります。影響を受けるバージョンは0.58.0から0.61.0までの複数の範囲にわたります。
🔍該当判定
- データ可視化ツール「Metabase」を自社サーバーやクラウドで利用している
- Metabaseのバージョンが 0.58.0〜0.61.1.3 の範囲内である
- Metabaseで「H2データベース」を利用している(初期設定のサンプルDB利用を含む)
- 一般ユーザーに「ネイティブクエリ(SQL直接入力)」の実行権限を与えている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受けるバージョンを使用している場合は、速やかに修正済みバージョン(0.58.15+, 0.59.12+, 0.60.6.3+, 0.61.1.4+)へアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Metabase リモートコード実行脆弱性 (CVE-2026-59827) 対応について
お疲れさまです。Metabaseの脆弱性に関する情報共有です。
■ 概要
Metabaseにおいて、H2データベース接続を利用したネイティブクエリ実行時に、不適切なデシリアライズにより任意のOSコマンドが実行される脆弱性が報告されました。認証済みでネイティブクエリ権限を持つユーザーが攻撃可能です。
■ 影響範囲
- Metabase >= 0.58.0 < 0.58.15
- Metabase >= 0.59.0 < 0.59.12
- Metabase >= 0.60.0 < 0.60.6.3
- Metabase >= 0.61.0 < 0.61.1.4
■ 対応手順
1. 現在利用しているMetabaseのバージョンを確認してください。
2. 影響を受けるバージョンである場合、以下の修正済みバージョンへアップデートしてください。
- 0.58.15, 0.59.12, 0.60.6.3, 0.61.1.4 以降
■ 参考情報
- https://github.com/metabase/metabase/security/advisories/GHSA-w95f-x9v9-wv36
対応優先度: 高
対応期限: 速やかに
お疲れさまです。Metabaseの脆弱性に関する情報共有です。
■ 概要
Metabaseにおいて、H2データベース接続を利用したネイティブクエリ実行時に、不適切なデシリアライズにより任意のOSコマンドが実行される脆弱性が報告されました。認証済みでネイティブクエリ権限を持つユーザーが攻撃可能です。
■ 影響範囲
- Metabase >= 0.58.0 < 0.58.15
- Metabase >= 0.59.0 < 0.59.12
- Metabase >= 0.60.0 < 0.60.6.3
- Metabase >= 0.61.0 < 0.61.1.4
■ 対応手順
1. 現在利用しているMetabaseのバージョンを確認してください。
2. 影響を受けるバージョンである場合、以下の修正済みバージョンへアップデートしてください。
- 0.58.15, 0.59.12, 0.60.6.3, 0.61.1.4 以降
■ 参考情報
- https://github.com/metabase/metabase/security/advisories/GHSA-w95f-x9v9-wv36
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Metabase Authenticated RCE (CVE-2026-59827)
Dear IT/Security Team,
We are sharing information regarding a critical vulnerability in Metabase.
■ Overview
An authenticated remote code execution (RCE) vulnerability exists in Metabase due to the insecure deserialization of Java objects returned by native H2 queries. An attacker with permissions to execute native queries can execute arbitrary OS commands on the server.
■ Affected Versions
- Metabase >= 0.58.0 < 0.58.15
- Metabase >= 0.59.0 < 0.59.12
- Metabase >= 0.60.0 < 0.60.6.3
- Metabase >= 0.61.0 < 0.61.1.4
■ Remediation
1. Verify the current version of your Metabase installation.
2. Update to the following patched versions or later:
- 0.58.15, 0.59.12, 0.60.6.3, or 0.61.1.4
■ Reference
- https://github.com/metabase/metabase/security/advisories/GHSA-w95f-x9v9-wv36
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a critical vulnerability in Metabase.
■ Overview
An authenticated remote code execution (RCE) vulnerability exists in Metabase due to the insecure deserialization of Java objects returned by native H2 queries. An attacker with permissions to execute native queries can execute arbitrary OS commands on the server.
■ Affected Versions
- Metabase >= 0.58.0 < 0.58.15
- Metabase >= 0.59.0 < 0.59.12
- Metabase >= 0.60.0 < 0.60.6.3
- Metabase >= 0.61.0 < 0.61.1.4
■ Remediation
1. Verify the current version of your Metabase installation.
2. Update to the following patched versions or later:
- 0.58.15, 0.59.12, 0.60.6.3, or 0.61.1.4
■ Reference
- https://github.com/metabase/metabase/security/advisories/GHSA-w95f-x9v9-wv36
Priority: High
Deadline: Immediate