ZeroHour
Story · 1 source · 1 articlefirst updated ()

Mathspace breach exposes data of 1,079,819 people via Metabase SQL injection flaw

highData breachexploited in the wildimportance 78CVE-2026-72898
What's new: First merged summary of this story. Mathspace's breach disclosure (theft confirmed September 3, 2026) is newly reported, and the incident is connected to the ongoing ShinyHunters-linked campaign against Metabase instances. All three reports agree on the affected count of 1,079,819 and the access/exfiltration timeline; SecurityWeek adds the CVE identifier (CVE-2026-72898) and Mathspace's delayed…
Merged summary · glm-5.3 · rewritten as coverage arrives

Mathspace disclosed that attackers exploited a SQL injection flaw in its self-hosted Metabase instance to steal personal data of 1,079,819 students, parents, teachers, and staff in Australia and New Zealand, part of a wider ShinyHunters-linked campaign…

Mathspace, an education platform, disclosed a data breach affecting 1,079,819 individuals — students, parents/guardians, teachers, and staff — in Australia and New Zealand. Attackers accessed Mathspace's self-hosted Metabase reporting system without legitimate login credentials by exploiting a SQL injection flaw. SecurityWeek identifies the flaw as zero-day CVE-2026-72898 (CVSS 10), which was patched upstream on August 6, 2026; Mathspace reportedly delayed patching until August 29 and skipped recommended post-patch compromise checks. Unauthorized access began August 10, 2026, data was downloaded on August 27, and the theft was confirmed September 3, 2026. Exposed data includes names, usernames, email addresses, country, account metadata, and login dates; no passwords, academic records, SSO tokens, or API credentials were taken, though affected individuals are warned of targeted phishing risk. The incident is part of a broader campaign against Metabase instances that also hit Framework, Tally, and Kilo Code (all disclosed in August 2026) and Trezor's fulfillment provider ShipMonk, with the ShinyHunters extortion gang claiming responsibility via extortion emails and leak-site listings.

  • 1,079,819 individuals affected across Australia and New Zealand (students, parents/guardians, teachers, and staff)
  • Attackers exploited a SQL injection flaw in Mathspace's self-hosted Metabase business intelligence instance to gain administrator access without legitimate login
  • SecurityWeek identifies the flaw as Metabase zero-day CVE-2026-72898 (CVSS 10), patched August 6, 2026; Mathspace delayed patching to August 29 and skipped recommended compromise checks
  • Unauthorized access began August 10, 2026; data was downloaded August 27; theft was confirmed September 3, 2026
  • Exposed data: names, usernames, email addresses, country, account metadata, and login dates; no passwords, academic records, SSO tokens, or API credentials were taken
  • Affected individuals warned of targeted phishing risk
  • Part of a wider campaign against Metabase instances: Framework, Tally, and Kilo Code disclosed similar breaches via the same flaw in August 2026; Trezor's provider ShipMonk was also affected
  • ShinyHunters claimed responsibility for the Metabase hacks, linked via extortion emails and leak-site listings

Coverage timeline

  1. · 8d ago
    BleepingComputer· 78
    Mathspace discloses data breach affecting over 1 million people

    Mathspace disclosed a Metabase breach exposing data of 1,079,819 students, parents, and staff in Australia and New Zealand.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-72898
Unauthenticated SQL Injection in Metabase Grants Admin Access

CVE-2026-72898 is a critical SQL injection flaw (CWE-89, CVSS 4.0 score of 10) in Metabase, a widely used open-source business intelligence platform. A remote, unauthenticated attacker can send crafted input to the '/reset_password' database endpoint to inject arbitrary SQL into the underlying database. Successful exploitation grants the attacker administrator access to the connected Metabase instance, with confidentiality, integrity, and availability impacts rated high in the CVSS 4.0 vector. Any organization running an affected Metabase instance, particularly one exposed to the internet, is at risk. The flaw is a zero-day being exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-11, and carries a 94.2% EPSS probability of exploitation within 30 days (100th percentile).

Do: Upgrade promptly to the fixed Metabase release identified in the vendor's security advisory (no version numbers were provided in the available data), as the flaw is being exploited in the wild and is on CISA's KEV list under BOD 26-04. Until patched, restrict internet access to Metabase and limit reachability of the '/reset_password' endpoint to trusted networks. Hunt for compromise by reviewing access logs for anomalous requests to the reset-password endpoint and checking for unexpected administrator accounts or changed admin credentials.

10.094% KEV PoC
  • Metabase
large≈10k–50k internet-exposed Metabase instances (tens of thousands)