metabase_database.details, the Column Storing Snowflake Credentials in Cleartext
Metabase’s CVE-2026-72898 patch closes an unauthenticated SQL injection in the password-reset endpoint, but it does not remove the admin accounts, API keys, or rotated connected-database credentials an attacker created before you upgraded. Here is what the retro-hunt actually looks like in ingress logs and the Metabase application database.