Sydney edtech company Mathspace has disclosed a data breach affecting 1,079,819 students, parents and guardians, teachers and staff across Australia and New Zealand. The cause was not an unavailable patch — it was a vulnerability-notification process that never escalated the advisory to anyone who could act.
The flaw: CVE-2026-72898, an unauthenticated SQL injection in Metabase's password reset endpoint, granting administrator access without a valid login. CVSS v3.1 base score 10.0 and CVSS v4.0 base score 10.0. Metabase published its advisory and patched versions on 6 August 2026; confirmation it had already been exploited in the wild as a zero-day followed on 8 August; CISA added it to the Known Exploited Vulnerabilities catalogue on 11 August.
Timeline. 6 Aug: advisory published; Mathspace's internal notification process fails to identify and escalate it. 10 Aug: earliest unauthorised access, four days after the patch became available. 27 Aug: the attacker downloads data from the Australian reporting database. 29 Aug: Mathspace patches, 23 days after the advisory, but does not perform the compromise checks Metabase recommended for potentially exposed instances. 3 Sep: a historical access log review confirms the breach, five days after patching; Metabase is taken offline and all API keys and database credentials rotated. 4 Sep: notifications to the OAIC, ASD's ACSC, New Zealand's Privacy Commissioner and NCSC, and Australian state and territory education departments. 5 Sep: public disclosure. 6 Sep: individual notifications begin. Twenty-four days from intrusion to detection; two days from detection to disclosure.
Data involved: user ID, username, first and last name, email address, country, time zone, user type, email verification status, last active date, last login date and date joined — not every field for every person. Explicitly not exposed: academic records, learning activities, results and assessments, passwords including hashes, authentication tokens, SSO credentials and API credentials. No password resets are being required, and as at its 8 September update Mathspace had seen no evidence the data has been published, distributed, sold or otherwise misused.
Attribution, read carefully: Mathspace states the identity of the attacker remains unknown and no group has claimed the breach. Separately, BleepingComputer has reported that ShinyHunters added Metabase to its leak site on 11 August and links the group to the wider campaign against Metabase instances — that is reporting about a campaign, not a confirmed attribution for Mathspace. Whether a ransom was demanded is unknown; asked by Information Age, Mathspace pointed back to its blog post.
What to take from it. First, shadow infrastructure needs an owner — if a self-hosted tool isn't on an asset inventory with a named owner subscribed to that vendor's advisories, it isn't being patched. Second, patching is not the finish line: if an internet-reachable system was exploitable, assume compromise until the logs prove otherwise. Third, internal tools hold external data — Metabase had no customer logins and no public front door, and was still the pivot to a million records because it was internet-reachable and connected to production data warehouses.
Mathspace's disclosure was unusually detailed and self-critical, naming its own process failures. Melbourne barrister Peter A Clarke, who writes on privacy law, called it excellent and said it provided real information to customers rather than the usual boilerplate.
Visit www.kinsoft.com.au to talk through your security and IT needs.
Sources: Mathspace incident disclosure (Alvin Savoy, CTO, 5 September 2026, updated 8 September); BleepingComputer; ACS Information Age; Cyber Daily; The Hacker News; Metabase advisory GHSA-vwf4-m7j8-wcjf; CISA KEV catalogue.