A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the component Rapids setproperty Primitive Handler. Executing a manipulation can lead to improper access controls. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-8752 is a medium-severity vulnerability in H2O-3 up to version 7402 affecting the Rapids setproperty primitive handler, allowing improper access control through remote manipulation of the exec function. The vulnerability stems from inadequate access controls in AstSetProperty.java and has public exploit code available.
تؤثر هذه الثغرة على معالج Rapids setproperty في H2O-3 وتسمح بالوصول غير المصرح به من خلال التلاعب بدالة exec. يمكن استغلال الثغرة عن بعد ويتوفر لها رمز استغلال عام.
This vulnerability in H2O-3 allows remote attackers to bypass access controls through the Rapids setproperty handler, potentially affecting organizations using H2O for machine learning and data analytics. The availability of public exploits increases the risk of exploitation against Saudi organizations.
Upgrade H2O-3 to a patched version beyond 7402 immediately. Implement network segmentation to restrict access to H2O instances. Apply principle of least privilege for user accounts accessing H2O. Monitor and audit all setproperty operations. Disable Rapids functionality if not required.
قم بترقية H2O-3 إلى إصدار مصحح بعد الإصدار 7402 فوراً. طبق تقسيم الشبكة لتقييد الوصول إلى مثيلات H2O. طبق مبدأ الامتيازات الأقل للحسابات التي تصل إلى H2O. راقب وتدقيق جميع عمليات setproperty. عطل وظيفة Rapids إذا لم تكن مطلوبة.