Known CVE
Juggle <= 1.6.0 - Unauthenticated Exposed H2 Database Console
Juggle ships the H2 database web console enabled and reachable from non-localhost by default. No application-level authentication covers the /h2-console path, and the shipped default datasource credentials (sa/juggle) are known. An unauthenticated remote attacker can reach the console and, using the default credentials, achieve OS command execution on the host via the H2 CREATE ALIAS Runtime.exec() technique.
CVE-2026-67208
Critical2026CVSS 9.8CWE-306
cve2026 · juggle · h2 · exposure · unauth · rce
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website