Mathspace breach leaks 1M Australian/NZ student records
Mathspace, a maths learning platform used in Australian and New Zealand schools, had a data breach. Attackers broke into an internal reporting tool and downloaded contact details for over a million students, parents, and teachers.
- Report priority
- High
- Victim
- Microsoft
What is known
Attackers sent forged requests to a password-reset feature in Mathspace's self-hosted Metabase reporting tool that let them sneak database commands past the login check, giving them administrator access without ever needing a real password.
What to do
If your child's school uses Mathspace, assume your name, email, username, and account details may be in the breach, since Mathspace says 1,079,819 accounts were affected.
Watch for a notification email from Mathspace, treat any Mathspace-related emails with extra suspicion since your email address may now be exposed, and change your Mathspace password as a precaution even though the company says passwords and hashes were not stolen.
Reported details
Metabase publishes a fix for a critical flaw in its password-reset feature on 6 August 2026. Mathspace does not apply the patch. On 10 August, attackers reach the still-vulnerable Metabase system through that same password-reset weakness and gain administrator access, then return on 27 August to copy out contact records for more than a million students, parents, and staff before Mathspace updates the software on 29 August.
The flaw, CVE-2026-72898, was an unauthenticated SQL injection in Metabase's password-reset API, letting attackers run arbitrary database queries and obtain admin access with no valid credentials. Metabase rated it CVSS 10.0 and shipped a fix on 6 August 2026; CISA added it to its Known Exploited Vulnerabilities list days later. Mathspace's vulnerability-notification process failed to escalate the advisory, so its self-hosted instance stayed exposed.
Attackers gained access on 10 August, exfiltrated data on 27 August, and Mathspace only patched on 29 August, discovering the earlier intrusion on 3 September during a log review. Exposed data was limited to account metadata (names, emails, usernames, timestamps); passwords, SSO tokens, and academic records were not affected.
References
- nvd.nist.gov · CVE-2026-72898 vdb entry
- blog.mathspace.co · mathspace-data-breach-what-happened-and-what-affected-users-should-know Cyber Security News
- underdefense.com · ai-soc-deployment-playbook-from-assessment-to-autonomy Cyber Security News
- bleepingcomputer.com · mathspace-discloses-data-breach-affecting-over-1-million-people BleepingComputer
- bleepingcomputer.com · idscan-sued-over-alleged-data-breach-affecting-153-million-drivers BleepingComputer
- infosecurity-magazine.com · healthcare-mckesson-investigates Infosecurity Magazine
- infosecurity-magazine.com · cisa-kev-microsoft-citrix Infosecurity Magazine
- neuracybintel.com · fbi-investigates-massive-drivers-license-data-breach-as-millions-of-identity-records-surface-on-the-dark-web NeuraCybIntel
- openwall.com · 7 Openwall oss-security
- openwall.com · 3 Openwall oss-security