Metabase Pre-Auth SQL Injection (CVE-2026-72898): CVSS 10.0, Actively Exploited
CVE-2026-72898 is an unauthenticated SQL injection in Metabase, scored CVSS 10.0 and already in CISA KEV. One request to /api/session/reset_password gives an attacker admin access and the credentials for every connected database. If you run Metabase, patch today.