top of page
perceptive_background_267k.jpg

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting …

Published:

30 juli 2026 om 00:00:00

Alert date:

30 juli 2026 om 23:05:50

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage, Zero-Day Vulnerabilities, Cloud & Virtualization

Juggle through version 1.6.0 contains a critical remote code execution vulnerability tracked as CVE-2026-67208. The vulnerability allows unauthenticated remote attackers to execute arbitrary OS commands by accessing an unprotected /h2-console endpoint. Attackers authenticate using default shipped credentials and exploit the H2 CREATE ALIAS Runtime.exec() technique to run arbitrary commands. When running the stock Docker image, exploitation results in root-level code execution. No authentication bypass is required as the endpoint is entirely unprotected. The vulnerability is especially dangerous in containerized deployments using default configurations. Remediation requires disabling or securing the H2 console endpoint and changing default credentials.

Technical details

Mitigation steps:

Affected products:

Juggle 1.6.0
H2 Database Console
Docker

Related links:

Related CVE's:

Related threat actors:

IOC's:

/h2-console

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page