What happened
Mathspace, an online mathematics platform used in schools across Australia and New Zealand, confirmed on September 3, 2026 that attackers had accessed and downloaded data from an internal reporting system built on a self-hosted instance of Metabase, the open-source business intelligence tool. The company began notifying school contacts on September 4 and started individual notifications on September 6, according to its own breach disclosure.
The breach affected 1,079,819 people in total: students, their parents or guardians, and school staff in Australia and New Zealand. That makes it one of the largest education-sector breaches disclosed in the region this year.
The vulnerability behind it
The root cause traces to a critical flaw in Metabase itself. Metabase disclosed the issue on August 6, 2026 through a GitHub security advisory (GHSA-vwf4-m7j8-wcjf) rated CVSS 10.0, the maximum possible severity, and shipped patched versions the same day. A CVE identifier, CVE-2026-72898, followed on August 10. The flaw sits in Metabase's password-reset endpoint, reachable without authentication, and allows an attacker to inject SQL commands and obtain administrator access to the instance, including stored credentials for any databases the instance connects to. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 11.
Metabase's advisory noted the flaw was being exploited in the wild before patched versions shipped. Mathspace was not the only customer caught in that window. Two other Metabase customers, data-infrastructure vendor Framework and the Python distribution company Anaconda, separately disclosed unauthorized access to customer data tied to the same flaw. Workflow-automation vendor n8n reported a similar compromise, saying the intrusion exposed 136 customer records containing names and email addresses.
Mathspace has acknowledged it did not patch in time. In its own disclosure, the company stated that its "existing vulnerability-notification process did not identify and escalate that advisory for action." Mathspace's investigation found unauthorized access to its systems beginning August 10, four days after Metabase's patch shipped, and identified that an attacker downloaded data from its Australian reporting database on August 27. Mathspace also says it had not completed the additional compromise checks Metabase recommended for instances exposed during the vulnerable window. That gap meant the intrusion went undetected when the company finally updated its Metabase instance on August 29, 23 days after the original advisory and two days after the data had already been taken. Mathspace says it is still investigating why the initial advisory was not escalated internally.
Who is affected and what was exposed
The exposed data includes usernames, first and last names, email addresses, country, time zone, user type, email-verification status, last-active date, last-login date, and account-creation date, per Mathspace's disclosure.
Mathspace says the breach did not expose the following: passwords or password hashes, authentication tokens, single sign-on credentials, API credentials, academic records, learning activity, results or assessment data. The exposed dataset also did not include records linking individual accounts to specific schools.
What affected users should know
Anyone notified by Mathspace or by their school should treat the exposed email addresses and names as compromised for phishing purposes, even though attackers did not take passwords or academic records. Because the breach did not expose password hashes or authentication tokens, Mathspace has not required account password resets as part of its response, based on its public disclosure. Parents, guardians and school staff who receive a notification should verify it was sent through their school's official channel before clicking any links, standard practice following any breach notification involving contact details for a population that includes minors.
What happens next
Mathspace notified the Office of the Australian Information Commissioner, the Australian Cyber Security Centre, New Zealand's Office of the Privacy Commissioner, and the New Zealand National Cyber Security Centre on September 4, the day after confirming the breach. Under Australia's Notifiable Data Breaches scheme, entities generally have up to 30 days to assess whether a breach is likely to cause serious harm, then must notify the OAIC and affected individuals as soon as possible once that assessment concludes. New Zealand's Privacy Act 2020 sets a looser "as soon as practicable" standard, though the Office of the Privacy Commissioner's stated expectation is notification within 72 hours of an organization becoming aware a breach is notifiable. Mathspace's one-day gap between confirming the breach and notifying regulators in both countries is faster than either baseline requires.
For organizations running self-hosted Metabase instances that have not yet applied the August 6 patch or checked for signs of exploitation from the pre-patch window, this is unresolved risk, not history. CISA's KEV listing already requires US federal agencies to remediate. The gap between Metabase's advisory and Mathspace's eventual patch is the specific failure the company has pointed to: an internal process that did not route a maximum-severity vendor advisory to anyone who could act on it.
Sources
Mathspace. "Mathspace data breach: what happened and what affected users should know." September 2026. https://blog.mathspace.co/mathspace-data-breach-what-happened-and-what-affected-users-should-know/
BleepingComputer. "Mathspace discloses data breach affecting over 1 million people." September 2026. https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/
SecurityWeek. "Mathspace Data Breach Exposes Over 1 Million People." September 2026. https://www.securityweek.com/mathspace-data-breach-exposes-over-1-million-people/
Help Net Security. "Mathspace breach exposes data on over a million students and parents." September 8, 2026. https://www.helpnetsecurity.com/2026/09/08/mathspace-data-breach-metabase-vulnerability/
Horizon3.ai. "Metabase SQL Injection | CVE-2026-72898." August 2026. https://horizon3.ai/attack-research/vulnerabilities/cve-2026-72898/
The Hacker News. "Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication." August 2026. https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html
Insurance Business (NZ). "NZ Privacy Act notification clock starts as offshore edtech breach lands." September 2026. https://www.insurancebusinessmag.com/nz/news/cyber/nz-privacy-act-notification-clock-starts-as-offshore-edtech-breach-lands-588883.aspx
OAIC. "About the Notifiable Data Breaches scheme." 2026. https://www.oaic.gov.au/privacy/notifiable-data-breaches/about-the-notifiable-data-breaches-scheme
OxygenIT. "Data Breach Notification in NZ: What Triggers It, Who You Must Tell, and How Fast." 2026. https://www.oxygenit.co.nz/data-breach-notification-nz/
