Misconfigured Supabase apps expose data in over 16,000 databases
Researchers discovered over 16,000 Supabase databases misconfigured to expose readable tables containing personally identifiable information, passwords, and authentication tokens. The exposed data includes sensitive records from various sectors such as a U.S. valet service, a Canadian immigration service, an India-based adult platform, a Philippines OTP service, and an African government consulate. The root cause is poor security configurations, including missing or ineffective row-level security policies and misuse of public keys, often linked to AI-assisted app development. Supabase users are advised to review security documentation to mitigate exposure risks.
AI Analysis
Technical Summary
Security researchers at UpGuard analyzed approximately 300,000 domains using Supabase and found more than 16,000 databases with misconfigurations exposing readable tables. These tables contained personally identifiable information (PII), passwords, authentication tokens, and in some cases credit card data. The exposures spanned multiple industries and countries, with notable incidents including over 100,000 customer records exposed by a U.S. valet service and nearly 5,000 user records with plaintext passwords at a Canadian immigration service. The misconfigurations stem from missing or ineffective row-level security policies and improper use of public keys. The researchers highlighted that many affected sites were created using AI coding agents, leading to human unawareness of insecure database configurations. UpGuard notified affected application owners and recommends reviewing Supabase's security guidelines to address these issues.
Potential Impact
The exposure of sensitive data such as PII, passwords, authentication tokens, credit card information, private messages, and SMS communications can lead to privacy violations, identity theft, unauthorized access, and potential fraud. The affected data spans multiple sectors and countries, increasing the risk of widespread harm. The root cause being misconfiguration rather than a software flaw means the impact depends on individual application security practices.
Mitigation Recommendations
No official patch is applicable as this is a misconfiguration issue. Supabase users should review and apply the platform's security documentation, including its advisors and API security guide, to identify and remediate exposure risks. Implementing proper row-level security policies and correct use of authentication keys is critical. Application owners should audit their database configurations, especially if using AI-assisted development tools, to ensure sensitive data is not publicly accessible.
Misconfigured Supabase apps expose data in over 16,000 databases
Description
Researchers discovered over 16,000 Supabase databases misconfigured to expose readable tables containing personally identifiable information, passwords, and authentication tokens. The exposed data includes sensitive records from various sectors such as a U.S. valet service, a Canadian immigration service, an India-based adult platform, a Philippines OTP service, and an African government consulate. The root cause is poor security configurations, including missing or ineffective row-level security policies and misuse of public keys, often linked to AI-assisted app development. Supabase users are advised to review security documentation to mitigate exposure risks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Security researchers at UpGuard analyzed approximately 300,000 domains using Supabase and found more than 16,000 databases with misconfigurations exposing readable tables. These tables contained personally identifiable information (PII), passwords, authentication tokens, and in some cases credit card data. The exposures spanned multiple industries and countries, with notable incidents including over 100,000 customer records exposed by a U.S. valet service and nearly 5,000 user records with plaintext passwords at a Canadian immigration service. The misconfigurations stem from missing or ineffective row-level security policies and improper use of public keys. The researchers highlighted that many affected sites were created using AI coding agents, leading to human unawareness of insecure database configurations. UpGuard notified affected application owners and recommends reviewing Supabase's security guidelines to address these issues.
Potential Impact
The exposure of sensitive data such as PII, passwords, authentication tokens, credit card information, private messages, and SMS communications can lead to privacy violations, identity theft, unauthorized access, and potential fraud. The affected data spans multiple sectors and countries, increasing the risk of widespread harm. The root cause being misconfiguration rather than a software flaw means the impact depends on individual application security practices.
Defensive Guidance
No official patch is applicable as this is a misconfiguration issue. Supabase users should review and apply the platform's security documentation, including its advisors and API security guide, to identify and remediate exposure risks. Implementing proper row-level security policies and correct use of authentication keys is critical. Application owners should audit their database configurations, especially if using AI-assisted development tools, to ensure sensitive data is not publicly accessible.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/","fetched":true,"fetchedAt":"2026-09-28T19:02:51.053Z","wordCount":767}
Threat ID: 6abab9dbf7a7c5410612d851
Added to database: 09/28/2026, 19:02:51 UTC
Last enriched: 09/28/2026, 19:02:55 UTC
Last updated: 09/29/2026, 01:55:41 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.