PT-2026-41542 · H2O.Ai · H2O-3

Vulnplusbot

·

Published

2026-05-17

·

Updated

2026-05-18

·

CVE-2026-8752

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions h2oai h2o-3 versions prior to 7402
Description A weakness in the Rapids setproperty Primitive Handler allows remote attackers to perform manipulations that lead to improper access controls and remote code execution. This issue specifically affects the exec() function within the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Incorrect Privilege Assignment

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-8752

Affected Products

H2O-3