A critical vulnerability (CVE-2026-72898) has been identified in the Metabase analytics platform. This issue allows remote, unauthenticated attackers to inject arbitrary SQL commands via the '/reset_password' database endpoint, potentially resulting in full administrator access to affected instances. Successful exploitation could enable data exfiltration, modification, or deletion, as well as lateral movement within compromised environments. The vulnerability affects all versions of Metabase prior to the latest security patch release. With a CVSS score of 10.0, this vulnerability represents an extreme risk due to its ease of exploitation and severe impact. Organizations are strongly advised to apply vendor-provided patches immediately. As a temporary mitigation, administrators should restrict network access to the '/reset_password' endpoint until updates can be deployed. Continuous monitoring of database logs for anomalous SQL activity is recommended to detect potential exploitation attempts. This vulnerability underscores the importance of timely patch management for database-facing applications.