Attackers used an unknown Metabase flaw to grab admin access and customer data before a patch shipped.