Online Maths Learning Platform Mathspace Disclosed Data Breach Impacts 1 Million Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Online maths learning platform Mathspace has confirmed a data breach that exposed the personal information of more than one million students, parents, guardians, and school staff across Australia and New Zealand, after attackers exploited a critical flaw in its internal reporting software.

The Sydney-based edtech company, which is widely used in classrooms across both countries, said on 3 September 2026 that unauthorized parties had accessed an internal reporting system and downloaded records belonging to students, their families, teachers, and Mathspace’s own employees.

In total, 1,079,819 people were affected, making it one of the largest education-sector breaches reported in the region this year.

Mathspace Data Breach

According to Mathspace’s disclosure, attackers exploited a security vulnerability in the company’s self-hosted Metabase installation, an open-source business intelligence tool used for internal reporting.

The flaw, tracked as CVE-2026-72898, was an unauthenticated SQL injection accessible through Metabase’s password-reset API endpoint, and it allowed attackers to inject arbitrary SQL commands and seize administrator access without needing valid credentials.

Metabase disclosed the critical, actively exploited vulnerability on 6 August 2026 and rated it the maximum CVSS score of 10.0, releasing patched versions the same day.

CISA added the flaw to its Known Exploited Vulnerabilities catalog within days, underscoring how quickly threat actors began weaponizing it against internet-facing instances.

Mathspace, however, did not act on the advisory in time. The company admitted that its “existing vulnerability-notification process did not identify and escalate that advisory for action.”

Unauthorized access to its Australian reporting database began on 10 August, just four days after the patch became available, and attackers exfiltrated data on 27 August.

Mathspace only updated its Metabase instance on 29 August, after a separate, later notice drew its attention to the issue, and it did not initially perform the additional compromise checks Metabase recommended for systems that had remained vulnerable during that window.

That gap meant the earlier intrusion went undetected until a review of historical access logs on 3 September confirmed unauthorized access had occurred before the patch was applied.

Incident Metric / Parameter Technical Observation & Details Operational Impact & Scope
Affected Individuals 1,079,819 unique accounts Students, parents, guardians, teachers, and Mathspace staff
Root Cause Flaw CVE-2026-72898 (CVSS 10.0) Unauthenticated SQL injection in Metabase password-reset API
Exposure Timeline Intrusion: Aug 10; Exfiltration: Aug 27; Patched: Aug 29 Four-day delay following public disclosure allowed initial breach
Exfiltrated Data Names, emails, usernames, account IDs, activity timestamps User account metadata and contact records; varied per individual
Protected Systems Passwords, hashes, SSO tokens, academic records, and grades Critical credentials and learning activity remained uncompromised
Incident Remediation Reporting system taken offline; logs audited; agencies alerted Advisory-escalation and post-patch validation workflows revised

The compromised records included user IDs, usernames, first and last names, email addresses, country, time zone, account type, email verification status, last active date, last login date, and account creation date. Not every field was present for every individual affected.

Mathspace emphasized that no passwords, password hashes, single sign-on tokens, API credentials, academic records, assessment results, or learning activity data were exposed, and that the stolen data did not directly link accounts to specific schools, though the company acknowledged this could be inferred for schools using identifiable email domains.

It said it has “no evidence so far” that the stolen data has been published, sold, or otherwise misused, and the attacker’s identity remains unknown.

Mathspace began emailing school contacts about the incident on 4 September and has urged recipients to verify any suspicious breach-related communication directly through its official data-breach response channel rather than clicking embedded links.

The company has taken the affected reporting system offline, notified schools, education departments, and cybersecurity authorities, and says it is revising its advisory-escalation and post-patch verification processes to prevent a recurrence.

Affected students, parents, and staff are advised to treat unexpected emails referencing Mathspace or their school with caution, avoid reusing passwords across services, and monitor accounts for unusual password-reset requests or login activity.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Online Maths Learning Platform Mathspace Disclosed Data Breach Impacts 1 Million Users appeared first on Cyber Security News.