The max-severity vuln, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.

Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data...

Metabase says a CVSS 10.0 zero-day SQL injection was exploited in the wild; the flaw can grant admin access and expose connected database data.