
Metabase Discloses Critical Zero-Day SQL Injection Flaw With Perfect CVSS Score
Metabase disclosed a critical zero-day SQL injection vulnerability (CVE-2026-72898) with a perfect CVSS score of 10, affecting versions 1.58 and up. The flaw allows attackers raw SQL access via the password reset endpoint, impacting companies like Kilo Code, Tally, Framework, n8n, and ChecklyHQ. Metabase has patched the issue and urges self-hosted users to upgrade immediately.
