TechNewsReel
Live

Framework Notifies All Customers After Metabase Zero-Day Breach

The modular laptop maker suffered a total compromise of its user contact database via a critical third-party vulnerability.

TechNewsReel Newsroom · August 10, 2026

Framework, the manufacturer of modular and repairable laptops, has notified its entire customer base that their personal information was accessed by hackers. The breach represents a total compromise of the company's user contact database.

According to reports from TechCrunch and btcnews.biz, the attackers gained access to four specific data points for every customer: full names, email addresses, phone numbers, and physical street addresses. The company confirmed that the breach was not a direct failure of its own internal systems but was instead executed through a third-party business intelligence tool called Metabase, which Framework utilizes for data analysis to optimize business operations and user experience.

The Metabase Vulnerability

The entry point for the attack was a zero-day vulnerability within the Metabase platform. Security analysis from BleepingComputer identifies the flaw as an unauthenticated SQL injection vulnerability. This specific exploit was rated with a CVSS score of 10.0, the highest possible severity rating, allowing attackers to bypass authentication and execute arbitrary queries to extract sensitive data from the connected database.

The Supply Chain Risk

This incident underscores the growing danger of supply chain vulnerabilities in the modern tech ecosystem. While Framework maintains a focus on hardware sustainability and repairability, this breach demonstrates that a company's security posture is only as strong as the third-party tools it integrates. When a trusted provider like Metabase suffers a critical flaw, the downstream impact can be catastrophic, exposing the sensitive data of an entirely different organization's customer base without the primary company having a direct flaw in its own code.

Industry Implications

For the industry, the Framework breach serves as a warning regarding the concentration of risk in business intelligence (BI) and analytics tools. These platforms often require deep, high-level access to customer databases to function, making them high-value targets for hackers. A single zero-day in a widely used BI tool can potentially grant attackers a "skeleton key" to the data of hundreds of different companies simultaneously.

What's Next

Framework has already begun the process of notifying all affected users. While the exposed data is limited to contact information rather than financial records or passwords, the scale of the breach—affecting 100% of the customer list—increases the risk of targeted phishing and social engineering attacks against Framework users. Security researchers will be watching for similar exploits across other companies using the same version of Metabase to determine if this was an isolated hit or part of a wider campaign.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.