Mathspace breach via Metabase SQL injection flaw exposes data on 1,079,819 people in Australia and New Zealand
Attackers exploited an unpatched self-hosted Metabase instance at education platform Mathspace, accessing from 10 August 2026 and downloading data on 27 August; ShinyHunters claimed responsibility. The same Metabase flaw (CVE-2026-72898) hit Framework, Tally,…
Mathspace disclosed a breach affecting 1,079,819 individuals in Australia and New Zealand. Help Net Security describes the victims as students, parents, and staff, while SecurityWeek additionally lists teachers. Attackers gained access to Mathspace's self-hosted Metabase business intelligence/reporting system without legitimate login, exploiting an unpatched SQL injection flaw identified by SecurityWeek as CVE-2026-72898, a CVSS 10 zero-day that was patched upstream on August 6; Mathspace reportedly delayed patching until August 29 and skipped recommended compromise checks. Unauthorized access began on 10 August 2026, and data was downloaded on 27 August. Exposed data includes names, usernames/user IDs, email addresses, country, login dates, and account metadata. Both reports agree no passwords, academic records, SSO/API tokens, or other credentials were taken. SecurityWeek reports that ShinyHunters claimed responsibility for the Metabase hacks, and Help Net Security notes that Framework, Tally, and Kilo Code disclosed similar breaches via the same Metabase SQL injection flaw in August 2026.
- 1,079,819 individuals affected in Australia and New Zealand (students, parents, and staff; SecurityWeek also lists teachers).
- Breach vector: unpatched self-hosted Metabase instance exploited via SQL injection; SecurityWeek identifies CVE-2026-72898, a CVSS 10 zero-day patched August 6.
- Unauthorized access began 10 August 2026; data downloaded 27 August 2026.
- Mathspace reportedly delayed patching to August 29 and skipped recommended compromise checks (per SecurityWeek).
- Exposed data: names, usernames/user IDs, email addresses, country, login dates, account metadata; no passwords, academic records, SSO tokens, or API credentials taken.
- ShinyHunters claimed responsibility for the Metabase hacks (per SecurityWeek).
- Same Metabase SQL injection flaw also breached Framework, Tally, and Kilo Code in August 2026.
- Sources disagree on victim composition: Help Net Security says students, parents, and staff; SecurityWeek says students, teachers, staff, and parents.
Coverage timelineoldest first · each row is one article
- · 8d agoMathspace breach exposes data on over a million students and parents
Help Net Security· 72
Mathspace confirmed attackers exploited an unpatched Metabase SQL injection flaw to steal personal data of 1,079,819 students, parents, and staff in Australia and New Zealand.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-72898 | Unauthenticated SQL Injection in Metabase Grants Admin Access CVE-2026-72898 is a critical SQL injection flaw (CWE-89, CVSS 4.0 score of 10) in Metabase, a widely used open-source business intelligence platform. A remote, unauthenticated attacker can send crafted input to the '/reset_password' database endpoint to inject arbitrary SQL into the underlying database. Successful exploitation grants the attacker administrator access to the connected Metabase instance, with confidentiality, integrity, and availability impacts rated high in the CVSS 4.0 vector. Any organization running an affected Metabase instance, particularly one exposed to the internet, is at risk. The flaw is a zero-day being exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-11, and carries a 94.2% EPSS probability of exploitation within 30 days (100th percentile). Do: Upgrade promptly to the fixed Metabase release identified in the vendor's security advisory (no version numbers were provided in the available data), as the flaw is being exploited in the wild and is on CISA's KEV list under BOD 26-04. Until patched, restrict internet access to Metabase and limit reachability of the '/reset_password' endpoint to trusted networks. Hunt for compromise by reviewing access logs for anomalous requests to the reset-password endpoint and checking for unexpected administrator accounts or changed admin credentials. | 10.0 | 94% | KEV PoC |
| large≈10k–50k internet-exposed Metabase instances (tens of thousands) |