Framework Faces Data Breach Due to Metabase Zero-Day Exploit

Framework Faces Data Breach Due to Metabase Zero-Day Exploit

First seen 7 Aug 2026, 18:12 UTC Heise.DeTechcrunch 80% similarity 69.0

Article Content

Browse articles
ThreatCluster

Framework, a laptop manufacturer, has reported a data breach affecting all customers due to a cyberattack on Metabase, its business intelligence provider. Hackers exploited a zero-day vulnerability in Metabase, allowing access to customer names, email addresses, phone numbers, and physical addresses, but not payment information. Framework has notified customers and is investigating the incident, while Metabase has released updates to secure its cloud instances. The vulnerability, which has a CVSS score of 10.0, affects all versions of Metabase from 58 to 63. Framework has changed access credentials for its Metabase cloud database and is working with IT forensics to assess the breach's impact. Customers are discussing the leak in forums, and a public statement from Framework is pending.

Key Points: • Framework's data breach affects all customers, with personal data stolen. • The breach was caused by a zero-day vulnerability in Metabase, CVSS 10.0. • Framework is investigating the incident and has changed access credentials.

ThreatCluster AI How this analysis works

Timeline

2026-08-03
Metabase identifies zero-day attack
Metabase disclosed a zero-day vulnerability that allowed hackers to access customer databases on its cloud servers.
Heise.De
2026-08-07
Framework notifies customers of data breach
Framework informed all customers about the breach, stating that hackers stole personal data but not payment information.
Techcrunch

Community

Browse all →