PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Misconfiguration·Updated Aug 13, 2026

Juggle <= 1.6.0 - Unauthenticated Exposed H2 Database Console

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-67208
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute arbitrary commands, resulting in root-level code execution when running the stock Docker image.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Juggleby somta
0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Juggle <= 1.6.0 - Unauthenticated Exposed H2 Database Console CVE-2026-67208 Scanner | S4E