A critical zero-day vulnerability in Metabase's SQL functionality poses a significant threat to the business analytics platform, granting malicious actors remote administrator access to the system and its downstream users. The maximum-severity flaw, which has not been assigned a CVE number, can be exploited by attackers to gain unauthorized control over the platform. As a result, the window for patching is rapidly shrinking, making it essential for organizations to assess their exposure to this vulnerability immediately. The potential blast radius of this vulnerability is substantial, given the widespread use of Metabase in various industries1. This vulnerability can have severe consequences, including data breaches and disruption of business operations, making it crucial for practitioners to take swift action to mitigate the risk. The lack of a patch or CVE number underscores the urgency of the situation, emphasizing the need for organizations to prioritize their security posture.