Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-3960

29
FAUCET Score

OVERVIEW CVE-2026-3960 is a critical remote code execution vulnerability affecting H2O-3 versions 3.46.0.9 and prior. The flaw exists in the unauthenticated REST API endpoint /99/ImportSQLTable and stems from an incomplete parameter blacklist that only restricts MySQL JDBC driver-specific dangerous parameters. Attackers can circumvent these controls by switching the JDBC protocol to PostgreSQL and leveraging PostgreSQL JDBC driver parameters such as socketFactory and socketFactoryArg to achieve arbitrary code execution. SEVERITY The vulnerability requires network access but presents a medium CVSS score of 5.9, primarily due to high attack complexity. However, the ability to execute arbitrary code on the H2O-3 server with process-level privileges represents a significant risk to affected deployments. The attack requires no authentication or user interaction, making it particularly dangerous for internet-exposed H2O-3 instances. The primary impact is system availability and integrity compromise rather than confidentiality. EXPLOITATION STATUS CVE-2026-3960 is currently listed on the Active Hot List, indicating active exploitation in the wild or high community attention. However, the EPSS score of 0.0019 suggests relatively low probability of exploitation compared to other vulnerabilities, and no public exploit code appears widely available. Organizations should prioritize upgrading to H2O-3 version 3.46.0.10 or later, particularly for internet-facing deployments.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.46.0.10CPE matchmatch criteria
cpe:2.3:a:h2o:h2o:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.9MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.94%
Probability of exploitation in next 30 days
EPSS Percentile
57.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0094 is in the 42nd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: ai.h2o:h2o-coreFixed in: 3.46.0.10

Vendor Advisories (1)

mavenGHSA-qmcv-hh7c-3m56medium

H2O-3 is Vulnerable to Code Injection

Apr 23, 2026

References

github.com / h2oai/h2o-3/commit/b9ae2d3c5220db2dc53753357a783e590364d044
Patch
huntr.com / bounties/6954fe04-b905-453f-8c53-205ac8377e0d
ExploitThird Party Advisory