All news
cybersecuritysaas

Framework Data Breach Tied to Metabase 0-Day Flaw

08 Aug 2026

Framework has disclosed a customer data breach traced back to a zero-day vulnerability in Metabase, the third-party business intelligence platform it uses internally. The incident exposed customer personally identifiable information (PII), though Framework says billing and payment data were not accessed.

What happened

According to Framework's disclosure, Metabase discovered the security incident and took three days to notify its business partners, including Framework. Once notified, Framework moved quickly — confirming the breach internally and alerting affected customers within six hours.

The exposed data included customer names and either emails or addresses. Sources differ on this detail: one part of the disclosure references "names and emails," while a separate risk statement in the same announcement refers to "names and addresses." It's unclear whether "addresses" means email addresses or physical addresses, leaving some ambiguity about the exact scope of exposed data.

The response

Framework says it is now reviewing how much data it shares with business intelligence tools like Metabase and plans to scope down access to only the data columns that are strictly necessary. This suggests the company is treating the incident as a prompt to tighten its broader data-sharing practices with third-party vendors, not just patch the immediate issue.

Several details remain unknown: the number of customers affected, the technical mechanics of the Metabase zero-day, whether Metabase has issued a patch, and whether Framework has looped in regulators or offered remediation such as credit monitoring. The exact time between initial exploitation of the vulnerability and Metabase's own discovery of it also hasn't been disclosed.

Why founders should care

This incident is likely relevant to any startup that pipes customer PII into third-party analytics or BI platforms — a common setup at early-stage companies. A few probabilistic takeaways:

  • Companies relying on shared BI infrastructure like Metabase are plausibly exposed to the same class of risk if similar vulnerabilities exist or emerge elsewhere. Founders using such tools may want to audit what customer data is actually being sent.
  • The three-day gap between Metabase's discovery and partner notification suggests vendor breach-disclosure timelines can meaningfully widen a company's risk window. Founders negotiating vendor contracts may benefit from pushing for faster breach-notification SLAs.
  • Framework's six-hour internal turnaround from notice to customer alert could be a useful benchmark — a fast confirmation-and-disclosure process may reduce reputational and customer-trust damage when a third-party vendor is compromised.
  • The move to limit BI tool access to only required data columns points to a broader best practice: minimizing PII exposure in every third-party integration, rather than assuming default access scopes are safe.

The bigger picture

With key facts still missing — including how many customers were affected and whether Metabase has patched the underlying flaw — this story is likely to develop further. For now, it stands as a reminder that supply-chain security extends beyond core infrastructure providers to the analytics and BI tools many startups treat as low-risk, back-office utilities.

Sources