๐Ÿ” CVE Alert

CVE-2026-67208

CRITICAL 9.8

Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute arbitrary commands, resulting in root-level code execution when running the stock Docker image.

CWE CWE-306 CWE-1188
Vendor somta
Product juggle
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for somta juggle

Be the first to know when new critical vulnerabilities affecting somta juggle are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

somta / Juggle
0 โ‰ค 1.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/somta/Juggle/issues/86 vulncheck.com: https://www.vulncheck.com/advisories/juggle-unauthenticated-rce-via-exposed-h2-console

Credits

Fatullayev Asadbek