Junglewise Threat Intelligence

CVE-2026-8750: h2oai h2o-3 path traversal in ImportFiles API

CVE-2026-8750 · Severity: medium · CVSS 5.3 · Published 2026-05-17

Technologies: H2O.ai H2O-3. Vendors: H2O.ai.

Executive brief

h2o-3 is an open-source machine learning platform used for data analysis and model building. A security vulnerability in its file import feature allows unauthorized individuals to remotely access and read sensitive files from the server's local storage. This could lead to the exposure of configuration files, system metadata, or other private data, potentially compromising the security of the entire host system.

Technical details

A path traversal vulnerability exists in the `importFiles` function within `h2o-core/src/main/java/water/persist/PersistNFS.java`. The `POST /3/ImportFiles` endpoint is exposed without authentication and accepts attacker-controlled filesystem paths. While the application implements a 'deny-glob' blacklist (blocking directories like /etc and /proc), it fails to restrict access to other sensitive local paths. An unauthenticated attacker can use this endpoint to import a local file as an H2O frame and subsequently retrieve the file's contents via the `GET /3/Frames/` API. The vulnerability stems from trusting user-supplied absolute paths and relying on an incomplete blacklist-based security model.

Affected products

  • h2oai h2o-3 up to 7402

Timeline

  • 2026-05-17: advisory: Vulnerability published by NVD/VulDB

References

Related threats