Metabase CVE-2026-72898: an unauthenticated SQL injection that hands over the data warehouse Opening Metabase is a business intelligence front end. People connect it to the warehouse, point it at tables, and build dashboards that executives read. To do that, it must hold database credentials, often with broad read access and frequently with write access. CVE-2026-72898 turned that design into a single unauthenticated request. The flaw is an SQL injection rated 10.0 under CVSS 3...