A missed advisory, a reporting tool, and 1,079,819 student and family records

Share this content

September 10, 2026

Mathspace did not get breached through its main app. It got breached through the reporting dashboard its own staff used to look at the data, a self-hosted copy of Metabase, the popular open-source business intelligence tool. And the fix was already available.

Mathspace

What happened

The timeline tells the story:

Date (2026)Event
Aug. 6Metabase patches CVE-2026-72898, a 10.0 critical SQL injection already exploited as a zero-day
Aug. 10Attackers gain admin access to Mathspace's Metabase server
Aug. 11CISA adds the flaw to its Known Exploited Vulnerabilities catalog
Aug. 27Attackers download data from Mathspace's Australian reporting database
Aug. 29Mathspace finally updates its Metabase instance
Sept. 3Mathspace confirms the theft

The flaw let an unauthenticated attacker inject SQL through Metabase's password reset page and take over the application. The extortion group ShinyHunters claimed the broader Metabase campaign, which also hit companies including Trezor, Framework and Tally.

In total, 1,079,819 students, parents, guardians, school staff and Mathspace employees in Australia and New Zealand were affected. Stolen fields included names, usernames, emails and account activity dates. Passwords, academic records and SSO credentials were not taken.

Mathspace was candid about the cause. Its vulnerability process never escalated Metabase's critical advisory, and it skipped the compromise checks Metabase recommended when it did patch. Because Metabase held live connections to other data stores, one forgotten internal tool became a door to everything it could query.

Why it matters for Texas institutions

Swap "Mathspace" for an institutional research office, an enrollment dashboard or a county's open-data team, and the story fits. Metabase and tools like it are everywhere in higher education and government because they are free, quick to stand up and great for answering questions about data.

They are also often run by analysts rather than IT, connected to production databases with powerful credentials, and missing from the patch cycle because they are "internal." Every edtech vendor holding your students' data has the same blind spots.

What your institution should do

  • Find your BI and reporting tools. Metabase, Superset, Redash and similar dashboards should be in your asset inventory with an owner.
  • Patch Metabase now and run the compromise checks. Look for unexpected admin accounts and queries.
  • Make sure advisories reach owners. If a department runs software, someone there must receive and act on its security notices.
  • Restrict access. Internal dashboards should sit behind SSO and VPN, not on the open internet.
  • Limit what dashboards can reach. Use read-only, least-privilege database accounts and avoid connecting reporting tools to every data store.
  • Ask your edtech vendors. Find out how they patch internal tools and how fast they would tell you about a breach.

RSOC is here to help

RSOC can scan for exposed reporting tools, verify versions, and help you review vendor risk for platforms that hold student data. Contact rsoc@utexas.edu.

Sources: BleepingComputer · SecurityWeek · Help Net Security · SafeState