Incident
Published 2026-09-05
Verified 2026-09-19

Mathspace: Metabase breach exposes ~1.08M AU/NZ student, parent and staff records

Mathspace's incident blog (published 5 September 2026, updated 6 September 2026) says attackers exploited a security vulnerability in its self-hosted Metabase internal-reporting install, obtaining administrator access without a legitimate login. Metabase published a critical advisory and patches on 6 August 2026; Mathspace says its vulnerability-notification process did not escalate that advisory, and it only updated on 29 August after a later Metabase notice. Unauthorised access dated from 10 August 2026 AEST; data was downloaded from the Australian reporting database on 27 August; Mathspace confirmed the historical access on 3 September. About 1,079,819 people in Australia and New Zealand were affected (students, parents/guardians, school staff, and Mathspace staff). Exported fields included user ID, username, names, email, country, time zone, user type, email-verification status, and last-active / last-login / date-joined. Passwords, SSO tokens, API credentials, academic records and school-link tables were not exposed. School notifications began 4 September. Mathspace notified the OAIC, ASD's ACSC, NZ OPC, NZ NCSC, and Australian state/territory education departments. The timeline matches Metabase CVE-2026-72898 (GHSA-vwf4-m7j8-wcjf); Mathspace's post does not name the CVE. Primary: Mathspace incident blog.

Exploited in Australia?
yes

Primary: Mathspace incident blog (updated 6 Sep 2026) · Vendor: Metabase GHSA-vwf4-m7j8-wcjf (CVE-2026-72898) · CVE: CVE-2026-72898 · Metabase — August 2026 vulnerability post

breaches australia cloud