A critical zero-day SQL Injection vulnerability, designated as CVE-2026-72898, has been disclosed by Metabase, a business intelligence platform provider, affecting versions 1.58 and later. This vulnerability has the highest possible severity score of 10, indicating a high level of risk. The flaw allows attackers to gain total access to sensitive credentials, tokens, API keys, and other data. The vulnerability was revealed on August 6, and its exploitation status is currently being discussed, particularly in relation to Meta. Experts warn that a perfect 10/10 CVSS score is rare and warrants concern1. The presence of this vulnerability in Metabase's platform poses a significant threat to customers' data security. So what matters to practitioners is that they must prioritize patching or monitoring their systems to prevent potential exploitation of this critical vulnerability.