PT-2026-34648 · H2O-3 · H2O-3

Published

2026-04-23

·

Updated

2026-05-19

·

CVE-2026-3960

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions H2O-3 versions prior to 3.46.0.10
Description An unauthenticated remote code execution issue exists in the REST API endpoint '/99/ImportSQLTable'. The flaw is caused by insufficient security controls in the parameter blacklist mechanism, which only filters dangerous parameters specific to the MySQL JDBC driver. An attacker can bypass these restrictions by changing the JDBC URL protocol to 'jdbc:postgresql:' and utilizing PostgreSQL JDBC driver-specific parameters, such as socketFactory and socketFactoryArg, to execute arbitrary code on the server with the privileges of the H2O-3 process.
Recommendations Update to version 3.46.0.10.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3960
GHSA-QMCV-HH7C-3M56

Affected Products

H2O-3