Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensitive credentials, tokens, API keys, and other data may have been exposed. The Metabase vulnerability revealed on August 6, designated CVE-2026-72898, is identified as critical, with a severity score of 10, the highest possible rating. It is present in versions 1.58 and up. “You don’t see a perfect 10/10 on CVSS often, but when you do, be worried,” noted David Shipley, CEO of Beauceron Security. SQL injection is “old school and painful, as there’s now working proof of concept exploit code.”