Framework loses customer data in Metabase zero-day attack
Jump to main content
Search
REG AD
PERSONAL TECH
Framework loses customer data in Metabase zero-day attack
Repairable hardware is little comfort when personal details escape
Carly Page
Carly<br>Page
Published<br>mon 10 Aug 2026 // 12:21 UTC
Modular laptop maker Framework has warned customers that an attacker exploited a zero-day at analytics provider Metabase to access names, email addresses, phone numbers, physical addresses, and login IP addresses, according to an email shared on Reddit.<br>For business customers, the exposed information may also include company names, phone numbers, VAT or Employer Identification Numbers (EINs), and billing email addresses. Framework said order and payment details were not affected.<br>"We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors," Framework said, adding that it's notifying regulators where required, though it noted that names, email addresses, phone numbers, and physical addresses don't cross the mandatory reporting threshold in many regions. Customers are getting the heads-up regardless.
REG AD
Framework didn't immediately reply to The Register's questions, but told TechCrunch that the breach had affected "all customers."
REG AD
The intrusion began with a zero-day vulnerability in Metabase, the business intelligence platform Framework uses to analyze its data.
Framework's latest laptop, the 13 Pro<br>Pic courtesy Framework
In its own blog post, Metabase said an attacker targeted its cloud service using a previously unknown vulnerability affecting versions 1.58 and later. The company blocked the endpoints used in the attack, patched the bug, and deployed the fix across its cloud service.<br>Framework's account provides a timeline for the break-in. Metabase discovered the attack on August 3 and notified Framework at 9am Pacific Time on August 6, telling the laptop maker that its instance had been vulnerable and that the attacker had successfully gained access to it.<br>Framework said it then rotated credentials for every database connected to its Metabase instance and found no changes to admin access or evidence that systems outside Metabase had been accessed. The company has also brought in a third-party forensics firm to investigate, and cautioned that its findings so far are preliminary.<br>According to Metabase, exploitation can allow an attacker to inject arbitrary SQL against the application's database and potentially gain administrator access. From there, they could alter configuration settings, steal credentials for databases connected to Metabase, query data those connections can access, and export the results.
MORE CONTEXT
Right to repair champ Framework punts modular 13in laptop with Core Ultra Series 3
A lot of product makers snub Right to Repair laws
Tariff-ied Framework pulls laptops, Keyboardio warns of keystroke sticker shock
Framework Desktop wows iFixit – even with the soldered RAM
Metabase told anyone running their own instance to patch immediately. If the vulnerable password-reset endpoint was exposed to the internet, admins have more work ahead of them: killing active sessions, checking for rogue API keys or admin accounts, rotating database credentials, and digging through logs for anything suspicious.<br>Framework is reviewing how customer information is made available through external analytics services, but hasn't yet said what changes that review might produce.<br>The breach lands during an already bumpy spell for Framework and its customers. In July, the repairable PC maker warned that the price it was being charged for LPCAMM2 memory used in its Laptop 13 Pro had more than doubled, forcing it to raise memory prices rather than swallow the increase. It also warned that CPU prices were heading upward and could push overall system prices higher in the coming weeks.
REG AD
Being able to replace almost every part of your laptop is handy. Finding your home address exposed through an analytics service is rather less so. ®
zero-day<br>laptop<br>security<br>personal tech
REG AD
AI AND ML
Agents made my retro tech safe to use again and showed their real value as testers of ideas
Let's all go a bit mad scientist and see if software can validate our wildest theories
AI AND ML
Zuck’s Chinese agentic prey escapes, will resume standalone ops
Manus AI will delete some data to satisfy legal requirements
paas and iaas
Why hybrid clouds break and what to do about it
SPONSORED EXPLAINER: There's nothing wrong with hybrid cloud. It's the one-size-fits-all strategy on top of it that's the problem.
AI AND ML
India’s central bank wants AI to approve loans that humans would reject
Regulator hopes for greater financial inclusion, without extra risk or blaming models for bad decisions
COLUMNISTS
Smart glasses are only smart if we train them to be good. Then they'll be fantastic
Just add smart humans – and a...