Alongside CVE-2026-8751 (the model-import deserialization bug covered separately), two more h2oai h2o-3 vulnerabilities were disclosed in the same batch — both, per NVD’s descriptions, following the same pattern of early vendor contact with no response before public release.
CVE-2026-8750: information disclosure via ImportFile API
Per NVD’s description, the importFiles function in PersistNFS.java (part of h2o-3’s ImportFile API) can be manipulated to leak information. NVD’s description states the attack can be executed remotely with public exploit code available. CVSS 3.1 base 5.3 (medium).
CVE-2026-8752: improper access control in the Rapids setproperty handler
Per NVD’s description, the exec function in AstSetProperty.java, part of h2o-3’s Rapids expression-execution engine, allows improper access control when manipulated. NVD’s description states the attack is remotely exploitable with public exploit code available. CVSS 3.1 base 5.3 (medium).
What we don’t yet have
Both records trace to VulDB submissions via NVD; no CISA KEV listing or vendor advisory is present. Confidence is medium, and — as with CVE-2026-8751 — no confirmed fixed version exists given the vendor’s lack of response to the disclosure.
Why this matters
Three separate h2o-3 findings from the same disclosure batch, all unacknowledged by the vendor, point to a pattern worth treating seriously as a whole rather than three isolated low-to-medium issues: an information-disclosure path in file import, an access-control gap in expression execution, and a deserialization bug in model import together suggest h2o-3’s server-side handlers broadly lack input validation appropriate for an untrusted-input environment. Deployments exposing h2o-3 to inputs from outside a fully trusted pipeline should treat all three as open, unpatched risks.
Frequently Asked Questions
What are CVE-2026-8750 and CVE-2026-8752? Two CVSS 5.3 medium-severity vulnerabilities in h2oai h2o-3: an information-disclosure bug in the ImportFile API’s file-import handler (8750), and an improper-access-control bug in the Rapids expression engine’s setproperty handler (8752).
Has h2oai issued fixes for these vulnerabilities? No confirmed fix is documented — NVD notes the vendor did not respond to the disclosures, matching the pattern for CVE-2026-8751.
Are these vulnerabilities being actively exploited? Public exploit code has been released for both per NVD’s descriptions, but neither is listed in CISA’s Known Exploited Vulnerabilities catalog as of this writing.
Data sourced from the National Vulnerability Database (NVD) and VulDB, aggregated September 2026. See more vulnerability intelligence.