Metabase, a provider of business intelligence and data visualization software, disclosed a maximum-severity zero-day vulnerability (CVSS 10.0) that is being exploited in the wild. The flaw allows unauthenticated SQL injection leading to full administrative access. Metabase has released patches for all affected versions and provided indicators of compromise to help detect attacks.