www.securityweek.com 8 Sept 2026, 10:47 UTC

Mathspace Breach Exposes Data of 1 Million After Metabase Flaw

Mathspace Breach Exposes Data of 1 Million After Metabase Flaw
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

MATHSPACE disclosed a data breach affecting over 1 million individuals after hackers compromised a self-hosted Metabase instance that served its reporting database. The intrusion was detected last week, reportedly about three weeks after the vulnerability was exploited as a zero-day. The flaw, tracked as CVE-2026-72898, is described as an SQL injection issue with a CVSS score of 10/10.

Metabase was patched on 6 August 2026, but Mathspace did not escalate the advisory promptly and upgraded the instance on 29 August, more than two weeks after the initial intrusion.

Mathspace’s incident notice states unauthorised access dates back to 10 August 2026, with information downloaded from the Australian reporting database on 27 August. The breach affected 1,079,819 students, teachers, staff, and parents/guardians across Australia and New Zealand. Exposed data included names, user IDs, usernames, email addresses, email verification status, time zone, country, date joined, and last login/active dates.

The company emphasised that no academic records, learning activity data, results, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed, and that there were no direct links between user accounts and their schools.

In response, Mathspace offlineed the Metabase instance, revoked API keys, disabled database access accounts, changed passwords, and exported logs for investigation. The firm is investigating why the initial advisory was not escalated and why theChecks recommended by Metabase were not completed sooner, and says it is updating its incident response and processes accordingly. Authorities in Australia have been notified, and affected individuals are being reached. The threat actors may use the stolen information for phishing.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline