# Framework discloses data breach via Metabase 0-day

_Thursday, August 6, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Framework discloses data breach via Metabase 0-day — Primary](https://us1.discourse-cdn.com/flex001/uploads/framework3/original/1X/f8ee93f9067eb34d64372000a4f27a89eaf1135b.jpeg)

Framework disclosed a data breach caused by a zero-day vulnerability in its Metabase business intelligence platform, the company said. The laptop maker notified customers that an attacker exploited the flaw to access a database containing personally identifiable information shared with the third-party analytics tool.

The breach exposed customer names, email addresses and complete billing addresses that Framework had transmitted to Metabase for business analysis. In a notification email, the company said it is evaluating the breadth and depth of data shared with business intelligence platforms and scoping down their access to only the columns required for analysis.

Framework's privacy policy states it does not sell personally identifiable information but permits sharing with trusted third parties who assist in operating the site or conducting business, provided they agree to keep information confidential. Customers criticized the company for sending unnecessary private data to Metabase and called for a full data privacy audit to prevent future incidents.

## Sources

- [community.frame.work](https://community.frame.work/t/framework-data-breach-discussion/83939)

---
Canonical: https://techandbusiness.org/newswire/HHAeGVZFMrjG_4hRRf4vup
Retrieved: 2026-08-07T15:22:25.094Z
Publisher: Tech & Business (techandbusiness.org)
