Framework loses customer data in Metabase zero-day attack

bananadonkey1 pts0 comments

Framework loses customer data in Metabase zero-day attack

Jump to main content

Search

REG AD

PERSONAL TECH

Framework loses customer data in Metabase zero-day attack

Repairable hardware is little comfort when personal details escape

Carly Page

Carly<br>Page

Published<br>mon 10 Aug 2026 // 12:21 UTC

Modular laptop maker Framework has warned customers that an attacker exploited a zero-day at analytics provider Metabase to access names, email addresses, phone numbers, physical addresses, and login IP addresses, according to an email shared on Reddit.<br>For business customers, the exposed information may also include company names, phone numbers, VAT or Employer Identification Numbers (EINs), and billing email addresses. Framework said order and payment details were not affected.<br>"We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors," Framework said, adding that it's notifying regulators where required, though it noted that names, email addresses, phone numbers, and physical addresses don't cross the mandatory reporting threshold in many regions. Customers are getting the heads-up regardless.

REG AD

Framework didn't immediately reply to The Register's questions, but told TechCrunch that the breach had affected "all customers."

REG AD

The intrusion began with a zero-day vulnerability in Metabase, the business intelligence platform Framework uses to analyze its data.

Framework's latest laptop, the 13 Pro<br>Pic courtesy Framework

In its own blog post, Metabase said an attacker targeted its cloud service using a previously unknown vulnerability affecting versions 1.58 and later. The company blocked the endpoints used in the attack, patched the bug, and deployed the fix across its cloud service.<br>Framework's account provides a timeline for the break-in. Metabase discovered the attack on August 3 and notified Framework at 9am Pacific Time on August 6, telling the laptop maker that its instance had been vulnerable and that the attacker had successfully gained access to it.<br>Framework said it then rotated credentials for every database connected to its Metabase instance and found no changes to admin access or evidence that systems outside Metabase had been accessed. The company has also brought in a third-party forensics firm to investigate, and cautioned that its findings so far are preliminary.<br>According to Metabase, exploitation can allow an attacker to inject arbitrary SQL against the application's database and potentially gain administrator access. From there, they could alter configuration settings, steal credentials for databases connected to Metabase, query data those connections can access, and export the results.

MORE CONTEXT

Right to repair champ Framework punts modular 13in laptop with Core Ultra Series 3

A lot of product makers snub Right to Repair laws

Tariff-ied Framework pulls laptops, Keyboardio warns of keystroke sticker shock

Framework Desktop wows iFixit – even with the soldered RAM

Metabase told anyone running their own instance to patch immediately. If the vulnerable password-reset endpoint was exposed to the internet, admins have more work ahead of them: killing active sessions, checking for rogue API keys or admin accounts, rotating database credentials, and digging through logs for anything suspicious.<br>Framework is reviewing how customer information is made available through external analytics services, but hasn't yet said what changes that review might produce.<br>The breach lands during an already bumpy spell for Framework and its customers. In July, the repairable PC maker warned that the price it was being charged for LPCAMM2 memory used in its Laptop 13 Pro had more than doubled, forcing it to raise memory prices rather than swallow the increase. It also warned that CPU prices were heading upward and could push overall system prices higher in the coming weeks.

REG AD

Being able to replace almost every part of your laptop is handy. Finding your home address exposed through an analytics service is rather less so. ®

zero-day<br>laptop<br>security<br>personal tech

REG AD

AI AND ML

Agents made my retro tech safe to use again and showed their real value as testers of ideas

Let's all go a bit mad scientist and see if software can validate our wildest theories

AI AND ML

Zuck’s Chinese agentic prey escapes, will resume standalone ops

Manus AI will delete some data to satisfy legal requirements

paas and iaas

Why hybrid clouds break and what to do about it

SPONSORED EXPLAINER: There's nothing wrong with hybrid cloud. It's the one-size-fits-all strategy on top of it that's the problem.

AI AND ML

India’s central bank wants AI to approve loans that humans would reject

Regulator hopes for greater financial inclusion, without extra risk or blaming models for bad decisions

COLUMNISTS

Smart glasses are only smart if we train them to be good. Then they'll be fantastic

Just add smart humans – and a...

framework metabase data laptop zero addresses

Related Articles