Skip to main content

Misconfigured Supabase apps expose data in over 16,000 databases

0
High
News
Published: 09/28/2026 (09/28/2026, 18:50:59 UTC)
Source: Bleeping Computer

Description

Researchers discovered over 16,000 Supabase databases misconfigured to expose readable tables containing personally identifiable information, passwords, and authentication tokens. The exposed data includes sensitive records from various sectors such as a U.S. valet service, a Canadian immigration service, an India-based adult platform, a Philippines OTP service, and an African government consulate. The root cause is poor security configurations, including missing or ineffective row-level security policies and misuse of public keys, often linked to AI-assisted app development. Supabase users are advised to review security documentation to mitigate exposure risks.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 19:02:55 UTC

Technical Analysis

Security researchers at UpGuard analyzed approximately 300,000 domains using Supabase and found more than 16,000 databases with misconfigurations exposing readable tables. These tables contained personally identifiable information (PII), passwords, authentication tokens, and in some cases credit card data. The exposures spanned multiple industries and countries, with notable incidents including over 100,000 customer records exposed by a U.S. valet service and nearly 5,000 user records with plaintext passwords at a Canadian immigration service. The misconfigurations stem from missing or ineffective row-level security policies and improper use of public keys. The researchers highlighted that many affected sites were created using AI coding agents, leading to human unawareness of insecure database configurations. UpGuard notified affected application owners and recommends reviewing Supabase's security guidelines to address these issues.

Potential Impact

The exposure of sensitive data such as PII, passwords, authentication tokens, credit card information, private messages, and SMS communications can lead to privacy violations, identity theft, unauthorized access, and potential fraud. The affected data spans multiple sectors and countries, increasing the risk of widespread harm. The root cause being misconfiguration rather than a software flaw means the impact depends on individual application security practices.

Defensive Guidance

No official patch is applicable as this is a misconfiguration issue. Supabase users should review and apply the platform's security documentation, including its advisors and API security guide, to identify and remediate exposure risks. Implementing proper row-level security policies and correct use of authentication keys is critical. Application owners should audit their database configurations, especially if using AI-assisted development tools, to ensure sensitive data is not publicly accessible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/","fetched":true,"fetchedAt":"2026-09-28T19:02:51.053Z","wordCount":767}

Threat ID: 6abab9dbf7a7c5410612d851

Added to database: 09/28/2026, 19:02:51 UTC

Last enriched: 09/28/2026, 19:02:55 UTC

Last updated: 09/29/2026, 01:55:41 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses