Junglewise Threat Intelligence

CVE-2026-8752: H2Oai H2O-3 improper access control in Rapids setproperty

CVE-2026-8752 · Severity: medium · CVSS 5.3 · Published 2026-05-17

Technologies: H2O.ai H2O-3. Vendors: H2O.ai.

Executive brief

A security vulnerability exists in H2O-3, a popular open-source machine learning platform. An unauthenticated attacker can remotely bypass security restrictions to enable a disabled feature that allows the import and execution of custom Java code (POJOs). This could allow an attacker to take full control of the server, access sensitive data, or disrupt machine learning operations.

Technical details

A critical logic flaw exists in the H2O-3 Rapids engine due to the public exposure of the 'setproperty' primitive via the /99/Rapids endpoint. This endpoint allows unauthenticated users to modify internal system properties across all cluster nodes. An attacker can exploit this to toggle the 'sys.ai.h2o.pojo.import.enabled' property to 'true', bypassing a default security gate designed to prevent the import of potentially malicious Java objects. Once enabled, the attacker can upload a malicious POJO source file and trigger its compilation and instantiation via the /3/ModelBuilders/generic endpoint, resulting in arbitrary code execution within the server environment. The vendor was reportedly contacted but has not provided a patch; remediation involves restricting access to debugging primitives and making security-sensitive properties immutable at runtime.

Affected products

  • h2oai h2o-3 up to 7402

Timeline

  • 2026-05-17: advisory: Vulnerability disclosed via VulDB and NVD
  • 2026-05-17: disclosed: Public exploit details released

References

Related threats