Mathspace - 1,079,819 People, a 23-Day Gap, and the Advisory That Never Reached Anyone
Tech Talks With Kinsoft by Steven Kinnas
Episode notes
Sydney edtech company Mathspace has disclosed a data breach affecting 1,079,819 students, parents and guardians, teachers and staff across Australia and New Zealand. The cause was not an unavailable patch — it was a vulnerability-notification process that never escalated the advisory to anyone who could act.
The flaw: CVE-2026-72898, an unauthenticated SQL injection in Metabase's password reset endpoint, granting administrator access without a valid login. CVSS v3.1 base score 10.0 and CVSS v4.0 base score 10.0. Metabase published its advisory and patched versions on 6 August 2026; confirmation it had already been exploited in the wild as a zero-day followed on 8 August; CISA added it to the Known Exploited Vulnerabilities catalogue on 11 August.
Timeline. 6 Aug: advisory published; Mathspace's internal notification process fails to i ...