CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67208

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-07-30
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute arbitrary commands, resulting in root-level code execution when running the stock Docker image.

⚡ Watch CVE-2026-67208

Get an email if CVE-2026-67208 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-67208

CVE.org record

Embed the live status

CVE-2026-67208 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67208 status](https://www.csirts.com/badge/CVE-2026-67208)](https://www.csirts.com/cve/CVE-2026-67208)