Mathspace Breach: 10/10 CVE Exploited, 1M+ Records Stolen
Attackers exploited CVE-2026-72898, a CVSS 10/10 SQL injection in self-hosted Metabase, to obtain admin access without a legitimate login. Mathspace's delayed patch—23 days after fixes shipped—allowed exfiltration of personal data belonging to 1,079,819 people. The incident underscores patch-latency risk and the need to complete vendor compromise checks after updating.
Beat this week
Last 7 days · Data Breaches
Impact not comparable yet. Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 100 percentage points.
This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- Attackers exploited CVE-2026-72898, a CVSS 10/10 SQL injection in self-hosted Metabase, to obtain admin access without a legitimate login.
- Mathspace's delayed patch—23 days after fixes shipped—allowed exfiltration of personal data belonging to 1,079,819 people.
- The incident underscores patch-latency risk and the need to complete vendor compromise checks after updating.
- SecurityWeek
- BleepingComputer
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1Mathspace disclosed a data breach affecting 1,079,819 students, teachers, staff, and parents/guardians in Australia and New Zealand.
- 2Attackers exploited CVE-2026-72898, a CVSS 10/10 SQL injection vulnerability in self-hosted Metabase, patched on August 6 after zero-day exploitation.
- 3Unauthorized access began on August 10, 2026 AEST, and data was downloaded from Mathspace's Australian reporting database on August 27, 2026.
- 4Mathspace did not upgrade its Metabase instance until August 29, 2026, and failed to complete Metabase's recommended compromise checks or identify the intrusion during the update.
- 5Stolen data includes names, user IDs, usernames, email addresses, email verification status, time zone, country, date joined, and last login and active dates.
- 6No academic records, learning activities, assessment results, password hashes, authentication tokens, SSO credentials, or API credentials were stolen; ShinyHunters claimed responsibility for hacking Metabase.
CVE-2026-72898 exploited in the wild as zero-day
Analysis
For security operations teams, the Mathspace breach illustrates the brutal arithmetic of patch latency: a 10/10 SQL injection in Metabase, patched on August 6 after zero-day exploitation, remained unpatched on Mathspace's self-hosted instance until August 29—while attackers had already exfiltrated data two days before the upgrade. It also shows that applying the patch isn't the same as completing vendor-recommended compromise checks: Mathspace missed the intrusion even during upgrade. Threat intel analysts should track ShinyHunters' claimed pivot against Metabase deployments as a data-extortion vector.
Mathspace, a Sydney-founded online mathematics platform used by thousands of schools in Australia, New Zealand, the United States, and the United Kingdom, has disclosed that attackers breached its self-hosted Metabase reporting system and stole personal data belonging to 1,079,819 students, teachers, school staff, and parents or guardians in Australia and New Zealand. The breach, confirmed on September 3, 2026, and disclosed in a Saturday blog post by CTO Alvin Savoy, stemmed from a known vulnerability in Metabase that Mathspace failed to patch for more than three weeks after a fix was available. According to the company's incident notice, unauthorized access began on August 10, 2026, Australian Eastern Standard Time, and data was downloaded from its Australian reporting database on August 27.
The breach, confirmed on September 3, 2026, and disclosed in a Saturday blog post by CTO Alvin Savoy, stemmed from a known vulnerability in Metabase that Mathspace failed to patch for more than three weeks after a fix was available.
The security defect at the center of the incident is CVE-2026-72898, an SQL injection vulnerability in Metabase with a maximum CVSS score of 10.0. Metabase patched the flaw on August 6 after it had already been exploited in the wild as a zero-day. Shortly after the patches were released, the extortion group ShinyHunters claimed responsibility for hacking Metabase, although Mathspace has not publicly attributed its specific intrusion to that group. Crucially, Mathspace did not apply the update until August 29, more than two weeks after attackers first accessed its instance, and the company acknowledged that it failed to escalate Metabase's critical advisory internally. It also did not complete the compromise checks Metabase recommended and did not identify the intrusion when it applied the update. The gap between the August 6 patch and the August 29 upgrade created a large window in which a public, in-the-wild vulnerability could be leveraged against unpatched infrastructure.
Mathspace says the exposed data includes names, user IDs, usernames, email addresses, email verification status, time zone, country, date joined, and last login and active dates. It does not include academic records, learning activities, results, assessment records, password hashes, authentication tokens, SSO credentials, or API credentials. That distinction matters for damage assessment: the absence of grades and credentials lowers the immediate harm, but the combination of student names, email addresses, usernames, and school-linked account metadata still enables phishing, social engineering, and account enumeration. Because the affected population includes minors, the breach also carries heightened privacy sensitivity and obligations under Australian and New Zealand privacy regimes, including the Australian Privacy Act and the Notifiable Data Breaches scheme.
For edtech providers and their school customers, the incident is a reminder that internal data tools are not separate from student-data security. Metabase is a widely used open-source business intelligence platform, and self-hosted instances often sit outside formal patching and asset-inventory programs. Mathspace's admission that the critical advisory was not escalated points to a process failure rather than an obscure technical exploit. The company has taken its Metabase instance offline, revoked API keys, disabled database access accounts, changed passwords, and exported logs for investigation. It is also investigating why checks were not completed sooner and says it is changing both escalation and compromise-check processes. Those are appropriate containment steps, but the breach may still invite regulatory scrutiny, parent and school inquiries, and ongoing monitoring for misuse of the downloaded dataset.
What to Watch
From a broader cybersecurity perspective, the Mathspace breach demonstrates the cascading impact of third-party and open-source tooling in the education sector. A single SQL injection in an analytics dashboard became the entry point for compromising data on more than one million people. The involvement of ShinyHunters, if tied to this intrusion, would signal a continuation of data-extortion operations against exposed business intelligence and database systems. Security teams should treat vendor advisories for self-hosted software as critical patch triggers, validate patch application with post-update compromise checks, and monitor for follow-on data leaks or extortion attempts. The absence of credentials in the stolen dataset is material, but identity and contact data still have monetization value on underground markets, especially at this scale.
Looking ahead, the practical test for Mathspace will be whether its process changes prevent recurrence and whether it can restore trust with the thousands of schools that rely on it. For the wider edtech and security communities, the timeline—patch released August 6, intrusion August 10, exfiltration August 27, upgrade August 29, confirmation September 3—will likely become a case study in why critical-vulnerability response cannot stop at patch release. The story also underscores the need for organizations to maintain complete inventories of self-hosted tools, prioritize vendor advisories based on exploit status, and run forensics even after patching, because attackers may already be inside.
Timeline
Timeline
Metabase patches CVE-2026-72898
Metabase releases fixes for a CVSS 10/10 SQL injection after exploitation in the wild as a zero-day. ShinyHunters later claims responsibility for hacking Metabase.
Unauthorized access begins
Attackers gain administrator access to Mathspace's self-hosted Metabase instance without a legitimate login.
Data exfiltrated
Threat actors download personal data from Mathspace's Australian reporting database.
Mathspace upgrades Metabase
The platform applies the update but does not complete Metabase's recommended compromise checks or identify the intrusion.
Breach confirmed
Mathspace confirms that unauthorized parties accessed the internal reporting system and downloaded data.
Public disclosure
CTO Alvin Savoy publishes a blog post disclosing the incident.
Source cluster
Primary reporting
- BleepingComputerMathspace discloses data breach affecting over 1 million people
Cite This Page
"Mathspace Breach: 10/10 CVE Exploited, 1M+ Records Stolen." Cyber Intelligence Brief, September 8, 2026. https://getcyberbrief.com/story/mathspace-metabase-cve-2026-72898-breach-1m
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |