A critical vulnerability (CVE-2026-50148) in Metabase enables remote code execution (RCE) through a flaw in the Snowflake JDBC driver. Attackers with permissions to configure database connections can exploit this by establishing a Snowflake connection to an attacker-controlled server. The vulnerability arises from the Snowflake JDBC driver's ability to write arbitrary files to the Metabase host, including overwriting legitimate driver files that execute within the Metabase process. This results in unrestricted code execution under the Metabase server's context. The flaw affects Metabase versions 1.54.0 through 1.60.4, with fixes implemented in subsequent releases. Organizations utilizing these versions are strongly advised to upgrade immediately to mitigate exploitation risks. The CVSS score of 10.0 underscores the severity, as successful exploitation could lead to full system compromise. No workarounds exist aside from applying the official patch. Affected components include Metabase, Snowflake JDBC driver, and Snowflake platform integrations.