An unauthenticated attacker can send crafted SQL through Metabase’s own password-reset endpoint and walk away with full administrator control of the instance, no login required.