A critical zero-day SQL injection vulnerability in Metabase allows unauthenticated attackers to gain administrator access to customer instances, enabling data theft and credential stealing. The flaw carries a maximum CVSS score of 10.0 and affects versions 1.58 and above. Both Metabase Cloud and self-hosted installations are vulnerable, with