Back to all lessons
Awareness Lessons
last month

Zero-Day in Metabase Exposes 1M+ Mathspace Users

Attackers exploited a zero-day vulnerability in Mathspace's self-hosted Metabase reporting tool to gain administrator-level access and exfiltrate personal data belonging to over one million students, parents, and staff. The root issue lies in the organization's failure to detect and mitigate a critical vulnerability in a third-party internal tool before attackers could weaponize it. Self-hosted analytics and reporting tools are frequently overlooked in vulnerability management programs, yet they often hold privileged access to sensitive databases. This incident highlights that any internet-accessible or internally networked tool — even one used for reporting — can become a critical attack surface if not actively monitored and patched. The 17-day dwell time between August 10 and August 27 also suggests insufficient detection and response capabilities.

Tactical Insight

Immediate actions

  • Audit all self-hosted third-party tools (e.g., Metabase, Grafana, Redash) and apply available patches or vendor mitigations immediately.
  • Restrict administrative interfaces of internal reporting tools to VPN or allowlisted IP ranges to reduce exposure.
  • Rotate all credentials and API keys associated with the compromised Metabase instance and any connected data sources.

Long-term improvements

  • Maintain a comprehensive inventory of all self-hosted software and include them in your vulnerability management and patching lifecycle.
  • Implement a formal third-party and open-source software risk assessment process before deploying any new internal tooling.
  • Apply the principle of least privilege to reporting tools, ensuring they only access the minimum data necessary for their function.

Detection measures

  • Deploy anomaly-based monitoring on internal tools to alert on unusual administrator logins, privilege escalations, or bulk data exports.
  • Subscribe to vulnerability feeds (e.g., NVD, vendor advisories) relevant to all self-hosted software in use across the organization.
  • Establish a maximum acceptable dwell time policy and validate it through regular threat-hunting exercises and log review.