Mathspace Data Breach Exposes Over 1 Million Users Via Critical Metabase Vulnerability
Online maths learning platform Mathspace has confirmed a data breach impacting over 1 million users, stemming from attackers exploiting a critical SQL injection vulnerability in its Metabase reporting software.

Online maths learning platform Mathspace has confirmed a data breach that exposed the personal information of more than one million students, parents, guardians, and school staff across Australia and New Zealand. The Sydney-based edtech company, widely used in classrooms, stated on September 3, 2026, that unauthorized parties had accessed an internal reporting system and downloaded records belonging to students, their families, teachers, and Mathspace employees. In total, 1,079,819 individuals were affected, marking it as one of the largest education-sector breaches reported in the region this year.
The attackers exploited a critical security vulnerability in the company's self-hosted Metabase installation, an open-source business intelligence tool used for internal reporting. The flaw, tracked as CVE-2026-72898, was an unauthenticated SQL injection accessible through Metabase's password-reset API endpoint. This allowed attackers to inject arbitrary SQL commands and gain administrator access without valid credentials.
Metabase disclosed the critical, actively exploited vulnerability on August 6, 2026, assigning it a maximum CVSS score of 10.0 and releasing patched versions the same day. The US Cybersecurity and Infrastructure Security Agency (CISA) quickly added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the rapid weaponization by threat actors against internet-facing instances.
However, Mathspace failed to act on the advisory in a timely manner. The company admitted that its "existing vulnerability-notification process did not identify and escalate that advisory for action." Unauthorized access to its Australian reporting database began on August 10, just four days after the patch became available, and attackers exfiltrated data on August 27.
Mathspace did not update its Metabase instance until August 29, after a separate, later notice drew its attention to the issue. Crucially, it did not perform the additional compromise checks recommended by Metabase for systems that had remained vulnerable during that window. This oversight meant the initial intrusion went undetected until a review of historical access logs on September 3 confirmed unauthorized access had occurred before the patch was applied.
The compromised records included user IDs, usernames, first and last names, email addresses, country, time zone, account type, email verification status, last active date, last login date, and account creation date. Mathspace emphasized that no passwords, password hashes, single sign-on tokens, API credentials, academic records, assessment results, or learning activity data were exposed. The company stated it has "no evidence so far" that the stolen data has been published or misused, and the attacker's identity remains unknown.
Mathspace began notifying affected schools on September 4 and has advised recipients to verify any suspicious breach-related communication directly through its official channels. The company has taken the affected reporting system offline, notified relevant authorities, and is revising its internal processes to prevent future recurrences. Affected individuals are urged to exercise caution with unexpected emails, avoid password reuse, and monitor their accounts for suspicious activity.