Mathspace did not get breached through its main app. It got breached through the reporting dashboard its own staff used to look at the data, a self-hosted copy of Metabase, the popular open-source business intelligence tool. And the fix was already available.
What happened
The timeline tells the story:
| Date (2026) | Event |
|---|---|
| Aug. 6 | Metabase patches CVE-2026-72898, a 10.0 critical SQL injection already exploited as a zero-day |
| Aug. 10 | Attackers gain admin access to Mathspace's Metabase server |
| Aug. 11 | CISA adds the flaw to its Known Exploited Vulnerabilities catalog |
| Aug. 27 | Attackers download data from Mathspace's Australian reporting database |
| Aug. 29 | Mathspace finally updates its Metabase instance |
| Sept. 3 | Mathspace confirms the theft |
The flaw let an unauthenticated attacker inject SQL through Metabase's password reset page and take over the application. The extortion group ShinyHunters claimed the broader Metabase campaign, which also hit companies including Trezor, Framework and Tally.
In total, 1,079,819 students, parents, guardians, school staff and Mathspace employees in Australia and New Zealand were affected. Stolen fields included names, usernames, emails and account activity dates. Passwords, academic records and SSO credentials were not taken.
Mathspace was candid about the cause. Its vulnerability process never escalated Metabase's critical advisory, and it skipped the compromise checks Metabase recommended when it did patch. Because Metabase held live connections to other data stores, one forgotten internal tool became a door to everything it could query.
Why it matters for Texas institutions
Swap "Mathspace" for an institutional research office, an enrollment dashboard or a county's open-data team, and the story fits. Metabase and tools like it are everywhere in higher education and government because they are free, quick to stand up and great for answering questions about data.
They are also often run by analysts rather than IT, connected to production databases with powerful credentials, and missing from the patch cycle because they are "internal." Every edtech vendor holding your students' data has the same blind spots.
What your institution should do
- Find your BI and reporting tools. Metabase, Superset, Redash and similar dashboards should be in your asset inventory with an owner.
- Patch Metabase now and run the compromise checks. Look for unexpected admin accounts and queries.
- Make sure advisories reach owners. If a department runs software, someone there must receive and act on its security notices.
- Restrict access. Internal dashboards should sit behind SSO and VPN, not on the open internet.
- Limit what dashboards can reach. Use read-only, least-privilege database accounts and avoid connecting reporting tools to every data store.
- Ask your edtech vendors. Find out how they patch internal tools and how fast they would tell you about a breach.
RSOC is here to help
RSOC can scan for exposed reporting tools, verify versions, and help you review vendor risk for platforms that hold student data. Contact rsoc@utexas.edu.
Sources: BleepingComputer · SecurityWeek · Help Net Security · SafeState