Skip to content

Known CVE

Juggle <= 1.6.0 - Unauthenticated Exposed H2 Database Console

Juggle ships the H2 database web console enabled and reachable from non-localhost by default. No application-level authentication covers the /h2-console path, and the shipped default datasource credentials (sa/juggle) are known. An unauthenticated remote attacker can reach the console and, using the default credentials, achieve OS command execution on the host via the H2 CREATE ALIAS Runtime.exec() technique.

CVE-2026-67208

Critical2026CVSS 9.8CWE-306

cve2026 · juggle · h2 · exposure · unauth · rce

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website