CVE-2026-72898: Metabase: Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint… | Rapid7 Vulnerability Database