ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire

Mathspace Data Breach Exposes Over 1 Million People

highData breach exploited in the wildimportance 68CVE-2026-72898
AI summary · glm-5.3-flash

Mathspace breach exposed data of 1,079,819 Australian and New Zealand users via exploited Metabase zero-day CVE-2026-72898; ShinyHunters claimed responsibility.

Mathspace disclosed a breach affecting 1,079,819 students, teachers, staff, and parents in Australia and New Zealand. Attackers exploited the Metabase SQL injection zero-day CVE-2026-72898 (CVSS 10), patched August 6, and accessed Mathspace's self-hosted instance from August 10; ShinyHunters claimed the Metabase hacks. Exposed data includes names, usernames, emails, and login dates; no passwords, academic records, or credentials were taken.

  • 1,079,819 individuals affected across Australia and New Zealand.
  • Intrusion exploited Metabase CVE-2026-72898, a CVSS 10 SQL injection zero-day exploited in the wild.
  • ShinyHunters claimed responsibility for hacking Metabase instances.
  • Data exposed: names, user IDs, emails, login dates; no passwords, tokens, or academic records.
  • Mathspace delayed patching to August 29 and skipped recommended compromise checks.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-72898
Unauthenticated SQL Injection in Metabase Grants Admin Access

CVE-2026-72898 is a critical SQL injection flaw (CWE-89, CVSS 4.0 score of 10) in Metabase, a widely used open-source business intelligence platform. A remote, unauthenticated attacker can send crafted input to the '/reset_password' database endpoint to inject arbitrary SQL into the underlying database. Successful exploitation grants the attacker administrator access to the connected Metabase instance, with confidentiality, integrity, and availability impacts rated high in the CVSS 4.0 vector. Any organization running an affected Metabase instance, particularly one exposed to the internet, is at risk. The flaw is a zero-day being exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-11, and carries a 94.2% EPSS probability of exploitation within 30 days (100th percentile).

Do: Upgrade promptly to the fixed Metabase release identified in the vendor's security advisory (no version numbers were provided in the available data), as the flaw is being exploited in the wild and is on CISA's KEV list under BOD 26-04. Until patched, restrict internet access to Metabase and limit reachability of the '/reset_password' endpoint to trusted networks. Hunt for compromise by reviewing access logs for anomalous requests to the reset-password endpoint and checking for unexpected administrator accounts or changed admin credentials.

10.094% KEV PoC
  • Metabase
large≈10k–50k internet-exposed Metabase instances (tens of thousands)
Full article399 words · extracted from securityweek.com · click to collapse

Mathspace, an online mathematics program for students, has disclosed a data breach that impacts over 1 million individuals.

The incident, it says, was discovered last week, roughly three weeks after hackers compromised its self-hosted Metabase instance using a known vulnerability.

The security defect, tracked as CVE-2026-72898 (CVSS score of 10/10) and described as an SQL injection issue, was patched on August 6, after it had been exploited in the wild as a zero-day.

Shortly after the patches were released, the notorious extortion group ShinyHunters claimed responsibility for hacking Metabase.

Mathspace failed to escalate Metabase’s critical advisory to prioritize patching and upgraded its instance on August 29, more than two weeks after hackers hit it.

“Our investigation identified unauthorised access dating back to 10 August 2026, Australian Eastern Standard Time. We confirmed that information was downloaded from our Australian reporting database on 27 August,” Mathspace says in an incident notice.

Advertisement. Scroll to continue reading.

Furthermore, Mathspace did not complete the compromise checks Metabase had recommended, and did not identify the intrusion upon applying the update.

“We are investigating why the initial advisory was not escalated and why those checks were not completed sooner. We are changing both processes as part of our incident response,” the online platform says.

Mathspace has taken its Metabase instance offline, revoked API keys, disabled the database access accounts, changed passwords, and exported the logs for investigation.

The data breach impacts 1,079,819 students, teachers, staff, and parents/guardians from Australia and New Zealand.

Hackers downloaded names, user IDs, usernames, email addresses, email verification status, time zone, country, date joined, and last login and active dates.

“No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools,” Mathspace says.

The platform warns that the threat actors may use the stolen information to mount phishing attacks, urging the potentially affected individuals to treat with extreme caution any unsolicited communication containing accurate references to the incident.

Mathspace reported the incident to the relevant authorities in Australia and, over the weekend, started notifying the potentially affected individuals.

Related: Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

Related: 153 Million Driver License Images Offered on Dark Web

Related: Ransomware Gang Claims Nutex Health Data Breach

Related: 9.5 Million Impacted by Aesto Health Data Breach

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/mathspace-data-breach-exposes-over-1-million-people/