PT-2026-34648 · H2O-3 · H2O-3
Published
2026-04-23
·
Updated
2026-05-19
·
CVE-2026-3960
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
H2O-3 versions prior to 3.46.0.10
Description
An unauthenticated remote code execution issue exists in the REST API endpoint '/99/ImportSQLTable'. The flaw is caused by insufficient security controls in the parameter blacklist mechanism, which only filters dangerous parameters specific to the MySQL JDBC driver. An attacker can bypass these restrictions by changing the JDBC URL protocol to 'jdbc:postgresql:' and utilizing PostgreSQL JDBC driver-specific parameters, such as
socketFactory and socketFactoryArg, to execute arbitrary code on the server with the privileges of the H2O-3 process.Recommendations
Update to version 3.46.0.10.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
H2O-3