A vulnerability described as problematic has been identified in h2oai h2o-3 up to 7402 . Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API . Such manipulation leads to information disclosure. This vulnerability is documented as CVE-2026-8750 . The attack can be executed remotely. Additionally, an exploit exists. The vendor was contacted early about this disclosure but did not respond in any way.