


Perceptive Security
SOC/SIEM Consultancy

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting …
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 21:05:50
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Zero-Day Vulnerabilities, Cloud & Virtualization
Juggle through version 1.6.0 contains a critical remote code execution vulnerability tracked as CVE-2026-67208. The vulnerability allows unauthenticated remote attackers to execute arbitrary OS commands by accessing an unprotected /h2-console endpoint. Attackers authenticate using default shipped credentials and exploit the H2 CREATE ALIAS Runtime.exec() technique to run arbitrary commands. When running the stock Docker image, exploitation results in root-level code execution. No authentication bypass is required as the endpoint is entirely unprotected. The vulnerability is especially dangerous in containerized deployments using default configurations. Remediation requires disabling or securing the H2 console endpoint and changing default credentials.
Technical details
Mitigation steps:
Affected products:
Juggle 1.6.0
H2 Database Console
Docker
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67208
https://github.com/somta/Juggle/issues/86
https://www.vulncheck.com/advisories/juggle-unauthenticated-rce-via-exposed-h2-console
Related CVE's:
Related threat actors:
IOC's:
/h2-console
This article was created with the assistance of AI technology by Perceptive.
