CVE-2026-67208
Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute arbitrary commands, resulting in root-level code execution when running the stock Docker image.
| CWE | CWE-306 CWE-1188 |
| Vendor | somta |
| Product | juggle |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for somta juggle
Be the first to know when new critical vulnerabilities affecting somta juggle are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
somta / Juggle
0 โค 1.6.0
References
Credits
Fatullayev Asadbek