Skip to content
Metabase zero-day: Data leak at laptop manufacturer Framework

Metabase zero-day: Data leak at laptop manufacturer Framework

Heise.De • August 7, 2026

Laptop manufacturer Framework has suffered a data leak and is warning its customers leaked information. and delivery data of private and commercial customers were lost – however, payment and order information were not, according to Framework. Attackers apparently exploited a zero-day vulnerability in Metabase; the database manufacturer has released updates and sealed its cloud instances.

In an email to its customers, which heise online has seen, the manufacturer writes that the following customer data was exfiltrated by the attack on Metabase:

To prevent future incidents, they are also examining how much information is shared with platforms for “Business Intelligence”, the email further states. In addition, they have informed the respective supervisory authorities and commissioned an IT forensics company to investigate. Framework has changed the access credentials for its Metabase cloud database.

Framework has made a name for itself with its repairable and upgradeable notebooks, such as the Laptop 13. No component is glued; battery, display, touchpad, and more can be easily replaced. Most recently, the company introduced the Laptop 13 Pro , marking a push into Linux as well. In the laptop manufacturer's forum , customers are discussing the extent of the leak; a public statement on the company blog or its social media accounts is still pending at this time.

The affected database provider, meanwhile, published its own security advisory . On August 3rd, they identified an attack on cloud instances of the company database that was carried out using a previously unknown security vulnerability – a “zero-day”. The vulnerability in Metabase (CVSS 10.0/10, severity critical , no CVE ID yet) affects all versions from 58 to 63, both the cloud solution operated by Metabase and its self-hosted version in customer networks.

The error apparently lies in the API endpoint for resetting user passwords – anyone who finds a POST request to /api/session/reset_password followed by a call to the endpoint /api/user/current in their access logs should consider their database system compromised. Updated versions are available:

Those who cannot immediately update their Metabase instance should block all access to /api/session/reset_password as a temporary protective measure. In case of suspected hostile takeover of the database, the security advisory on Github contains further information. Cloud customers, Metabase states, are already secure – however, the company does not mention how many have already had data exfiltrated.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Attack Types (1)

Companies (2)

Domains (1)