The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.

Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data...

Metabase says a CVSS 10.0 zero-day SQL injection was exploited in the wild; the flaw can grant admin access and expose connected database data.