CVE-2026-8751 is a high-severity (CVSS 3.1 base 7.3) insecure-deserialization vulnerability in h2oai’s h2o-3, an open-source machine learning platform, affecting builds up to 7402.
What the vulnerability does
Per NVD’s description, the flaw is in importBinaryModel, a function in h2o-core/src/main/java/hex/Model.java responsible for loading a serialized model file. Manipulating this import path results in unsafe deserialization — a well-established vulnerability class where an attacker-supplied serialized object, rather than a trusted one, is deserialized without adequate validation, typically enabling remote code execution depending on what classes are reachable on the application’s classpath. NVD’s description states the attack can be carried out remotely and that exploit code has been publicly released.
Disclosure history
NVD’s own description notes the vendor was contacted early about this disclosure but did not respond in any way, after which the finding was released to the public. This is a meaningful data point distinct from the technical severity: no vendor acknowledgment means there is no confirmed timeline for an official fix, and organizations can’t rely on an upcoming patch as a mitigation plan.
What we don’t yet have
This record traces to a VulDB submission via NVD; no CISA KEV listing or vendor advisory is present in our ingested data. Confidence is medium, and we don’t have a confirmed fixed version — given the unacknowledged disclosure, check h2oai’s own release notes directly for whether builds after 7402 address this.
Why this matters
h2o-3 is used to load and run models that may originate from outside a fully trusted pipeline (shared model files, third-party training runs, CI artifacts) — exactly the scenario an insecure model-import deserialization bug threatens. Any deployment that imports binary model files from a source it doesn’t fully control should treat this as an active, unpatched risk given the lack of vendor response, and restrict model imports to trusted sources until a fix is confirmed.
Frequently Asked Questions
What is CVE-2026-8751? A CVSS 7.3 high-severity insecure-deserialization vulnerability in h2oai h2o-3’s binary model import handler, affecting builds up to 7402.
Has h2oai issued a fix for CVE-2026-8751? No confirmed fix is documented in our data — NVD notes the vendor did not respond to the initial disclosure.
Is CVE-2026-8751 being actively exploited? Public exploit code has been released per NVD’s description, but it is not listed in CISA’s Known Exploited Vulnerabilities catalog as of this writing.
Data sourced from the National Vulnerability Database (NVD) and VulDB, aggregated September 2026. See more vulnerability intelligence.