Mathspace Data Breach Exposes 1 Million Users’ Personal Info
Key Takeaways Mathspace, an online mathematics learning platform, experienced a data breach impacting over one million users. Attackers exploited CVE-2026-72898, a critical SQL injection...
Key Takeaways
- Mathspace, an online mathematics learning platform, experienced a data breach impacting over one million users.
- Attackers exploited CVE-2026-72898, a critical SQL injection vulnerability in the company’s internal Metabase reporting software.
- The breach exposed personal information including names, email addresses, and account details for students, parents, guardians, and school staff in Australia and New Zealand.
- Passwords, academic records, and sensitive learning activity data were not compromised.
- Mathspace failed to patch the critical vulnerability in a timely manner, allowing attackers to exfiltrate data.
Mathspace Breach Exposes Over 1 Million Users Due to Unpatched Critical Flaw
Mathspace, a prominent online learning platform for mathematics, has confirmed a significant data breach affecting more than one million users across Australia and New Zealand. The incident stemmed from the exploitation of a critical vulnerability in the company’s internal reporting software, leading to unauthorized access and exfiltration of personal data belonging to students, parents, guardians, and school personnel.
Table Of Content
On September 3, 2026, the Sydney-based educational technology firm disclosed that malicious actors had infiltrated an internal reporting system. This compromise resulted in the download of records associated with students, their families, educators, and even Mathspace’s own employees. In total, 1,079,819 individuals were impacted, marking one of the largest education-sector breaches in the region this year.
Exploitation of CVE-2026-72898
According to Mathspace’s disclosure, the breach was facilitated by a security flaw in their self-hosted Metabase installation, an open-source business intelligence tool utilized for internal reporting. The vulnerability, identified as CVE-2026-72898, is an unauthenticated SQL injection. This critical flaw was present in Metabase’s password-reset API endpoint, allowing attackers to execute arbitrary SQL commands and gain administrator privileges without requiring valid credentials.
Metabase publicly disclosed this severe vulnerability on August 6, 2026, assigning it the highest possible CVSS score of 10.0 and releasing patches on the same day. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) promptly added the flaw to its Known Exploited Vulnerabilities catalog, highlighting the rapid weaponization of this vulnerability by threat actors against internet-facing systems.
Delayed Patching and Detected Intrusion
Despite the immediate public disclosure and availability of a patch, Mathspace failed to address the vulnerability in a timely manner. The company admitted that its “existing vulnerability-notification process did not identify and escalate that advisory for action.” Consequently, unauthorized access to its Australian reporting database commenced on August 10, merely four days after the fix was released. Data exfiltration then occurred on August 27.
Mathspace only updated its Metabase instance on August 29, following a separate, later notification that brought the issue to their attention. Crucially, the company initially omitted the additional compromise checks recommended by Metabase for systems that had remained unpatched during the exploitation window. This oversight meant the initial intrusion went undetected until a subsequent review of historical access logs on September 3 confirmed the unauthorized access prior to the patch application.
Compromised Data and Remedial Actions
The exfiltrated records included user IDs, usernames, first and last names, email addresses, country, time zone, account type, email verification status, last active date, last login date, and account creation date. The specific fields present varied for each affected individual. Mathspace has confirmed that no passwords, password hashes, single sign-on tokens, API credentials, academic records, assessment results, or learning activity data were compromised. The company also noted that while the stolen data did not directly link accounts to specific schools, such associations could be inferred for institutions using identifiable email domains.
Mathspace stated that there is “no evidence so far” that the stolen data has been published, sold, or otherwise misused, and the identity of the attacker remains unknown. In response to the breach, Mathspace has taken the affected reporting system offline, notified relevant schools, education departments, and cybersecurity authorities. The company is also revising its advisory-escalation and post-patch verification processes to bolster its defenses against future incidents.
What You Should Do
- Exercise extreme caution with any unexpected emails or communications that claim to be from Mathspace or your school, especially if they mention the data breach. Verify legitimacy through official channels before clicking links.
- Avoid reusing passwords across different online services. If you have used the same password for Mathspace and other accounts, change it immediately for all affected services.
- Monitor your online accounts for any unusual password-reset requests or suspicious login activity.
- Be vigilant for potential phishing attempts that may leverage the exposed personal information to gain further access to your accounts.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.