Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own advisory says the vulnerability carries a CVSS score of 10.0, and it let an unauthenticated attacker inject arbitrary SQL straight into the…