OVERVIEW CVE-2026-3960 is a critical remote code execution vulnerability affecting H2O-3 versions 3.46.0.9 and prior. The flaw exists in the unauthenticated REST API endpoint /99/ImportSQLTable and stems from an incomplete parameter blacklist that only restricts MySQL JDBC driver-specific dangerous parameters. Attackers can circumvent these controls by switching the JDBC protocol to PostgreSQL and leveraging PostgreSQL JDBC driver parameters such as socketFactory and socketFactoryArg to achieve arbitrary code execution. SEVERITY The vulnerability requires network access but presents a medium CVSS score of 5.9, primarily due to high attack complexity. However, the ability to execute arbitrary code on the H2O-3 server with process-level privileges represents a significant risk to affected deployments. The attack requires no authentication or user interaction, making it particularly dangerous for internet-exposed H2O-3 instances. The primary impact is system availability and integrity compromise rather than confidentiality. EXPLOITATION STATUS CVE-2026-3960 is currently listed on the Active Hot List, indicating active exploitation in the wild or high community attention. However, the EPSS score of 0.0019 suggests relatively low probability of exploitation compared to other vulnerabilities, and no public exploit code appears widely available. Organizations should prioritize upgrading to H2O-3 version 3.46.0.10 or later, particularly for internet-facing deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.46.0.10CPE matchmatch criteria | cpe:2.3:a:h2o:h2o:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.