Metabase Zero-Day (CVE-2026-72898): CVSS 10.0 SQL Injection Exploited in the Wild
CVE-2026-72898 is a CVSS 10.0 unauthenticated SQL injection in Metabase's password-reset endpoint, exploited in the wild to hand attackers admin access. Patch to a fixed release now, or block the endpoint.






