ZeroHour
Story · 1 source · 1 articlefirst updated ()

Mathspace data breach exposes 1,079,819 users in Australia and New Zealand via exploited Metabase zero-day CVE-2026-72898

highData breachimportance 78CVE-2026-72898
What's new: Initial merge; no previous summary existed. Relative to the first report (DataBreaches.net, 2026-09-07), this merged story adds: identification of the breached system as a self-hosted Metabase instance; the vulnerability (SQL injection zero-day CVE-2026-72898, CVSS 10); the full timeline (access from 2026-08-10, exfiltration 2026-08-27, confirmation 2026-09-03); the detailed exposed/not-exposed…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Mathspace confirmed on 2026-09-03 that attackers exploited an unpatched self-hosted Metabase reporting instance (SQL injection zero-day CVE-2026-72898, CVSS 10) to download personal data of 1,079,819 students, parents/guardians, teachers, and staff in…

On 2026-09-03, Mathspace publicly confirmed a breach affecting 1,079,819 people in Australia and New Zealand, including students, parents or guardians, teachers, and Mathspace staff. Attackers gained administrator access without any legitimate login to the company's self-hosted Metabase reporting system, exploiting the SQL injection zero-day CVE-2026-72898 (CVSS 10), which was patched upstream on 2026-08-06 (SecurityWeek). Unauthorized access began on 2026-08-10 and data was downloaded on 2026-08-27. Exposed data includes names, usernames/user IDs, email addresses, country, account metadata, and login dates; no passwords, academic records, SSO tokens, API credentials, or school-account links were taken. BleepingComputer reports affected individuals are being warned of targeted phishing risk, and SecurityWeek reports Mathspace delayed applying the patch to 2026-08-29 and skipped recommended compromise checks. ShinyHunters claimed responsibility for hacking the Metabase instances (SecurityWeek), with BleepingComputer linking the campaign to ShinyHunters via extortion emails and leak-site listings. Other Metabase users breached in the same campaign during August 2026 include Framework, Tally, and Kilo Code (Help Net Security), as well as Trezor's provider ShipMonk (BleepingComputer). Note: DataBreaches.net's initial report described the breached system only as an 'internal reporting system' without identifying Metabase or the vulnerability; this was identified as Metabase with the CVE by the three later reports.

  • 1,079,819 individuals affected across Australia and New Zealand (consistent across all four reports)
  • Affected groups: students, parents/guardians, teachers, and Mathspace staff
  • Attack vector: exploited self-hosted Metabase reporting instance; attackers gained administrator access without legitimate login
  • Vulnerability: Metabase SQL injection zero-day CVE-2026-72898, CVSS 10 (SecurityWeek); BleepingComputer and Help Net Security describe the instance as unpatched at the time of intrusion
  • Timeline: unauthorized access began 2026-08-10; data downloaded/exfiltrated 2026-08-27; breach publicly confirmed 2026-09-03
  • CVE-2026-72898 was patched upstream on 2026-08-06; SecurityWeek reports Mathspace delayed patching to 2026-08-29 and skipped recommended compromise checks
  • Exposed data: names, usernames/user IDs, email addresses, country, account metadata, and login dates
  • Not exposed: passwords, academic records, SSO tokens, API credentials, or school-account links

Coverage timeline

  1. · 9d ago
    DataBreaches.net· 42
    Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ

    Mathspace confirmed a breach affecting 1,079,819 people in Australia and New Zealand after unauthorized parties downloaded user data from an internal system.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-72898
Unauthenticated SQL Injection in Metabase Grants Admin Access

CVE-2026-72898 is a critical SQL injection flaw (CWE-89, CVSS 4.0 score of 10) in Metabase, a widely used open-source business intelligence platform. A remote, unauthenticated attacker can send crafted input to the '/reset_password' database endpoint to inject arbitrary SQL into the underlying database. Successful exploitation grants the attacker administrator access to the connected Metabase instance, with confidentiality, integrity, and availability impacts rated high in the CVSS 4.0 vector. Any organization running an affected Metabase instance, particularly one exposed to the internet, is at risk. The flaw is a zero-day being exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-11, and carries a 94.2% EPSS probability of exploitation within 30 days (100th percentile).

Do: Upgrade promptly to the fixed Metabase release identified in the vendor's security advisory (no version numbers were provided in the available data), as the flaw is being exploited in the wild and is on CISA's KEV list under BOD 26-04. Until patched, restrict internet access to Metabase and limit reachability of the '/reset_password' endpoint to trusted networks. Hunt for compromise by reviewing access logs for anomalous requests to the reset-password endpoint and checking for unexpected administrator accounts or changed admin credentials.

10.094% KEV PoC
  • Metabase
large≈10k–50k internet-exposed Metabase instances (tens of thousands)