A CVSS 10 exploited in the wild, with no CVE — Metabase found it when its own cloud was breached
2026-08-12Security
Unauthenticated SQL injection through the password-reset endpoint, every release from 1.58 onward affected, and confirmed victims already naming what was taken. It is tracked as a GitHub advisory, which means NVD-driven scanners will not see it.