Misconfigured Supabase apps expose data in over 16,000 databases
TLDR
- Researchers at UpGuard found more than 16,000 misconfigured Supabase databases exposing readable data tables, out of roughly 300,000 domains scanned for Supabase usage.
- The root cause is missing or ineffective row-level security policies combined with misuse of public API keys, letting anyone query tables that should have been restricted.
- Over half of the affected databases exposed personally identifiable information; smaller subsets contained plaintext passwords, authentication tokens, or credit card data.
- UpGuard links much of the pattern to AI-assisted development, where site creators using AI coding tools were often unaware of their database's actual security configuration.
Researchers at cyber risk management firm UpGuard examined roughly 300,000 domains showing signs of Supabase usage, checking each for an accessible "users" table or similarly named table, and found more than 16,000 databases with misconfigured security exposing readable data.1 The exposures stemmed from missing or ineffective row-level security policies and misuse of public keys, which together left tables queryable by anyone rather than restricted to authorised requests.1
In over half of the affected databases, researchers found personally identifiable information; smaller subsets contained plaintext passwords and authentication tokens, and a limited portion reportedly included credit card data.1 Examples cited include a US valet service exposing more than 100,000 customer records with contact details, licence plates and visit history; a Canadian immigration service exposing nearly 5,000 user records including 884 plaintext passwords; an India-based adult creator platform exposing sensitive identity and payment data along with over 100,000 private messages; a Philippines-based OTP service exposing more than 2,000 users and 100,000 SMS messages; and an African government consulate exposing 25,000 people's records, including addresses and emergency housing locations.1
UpGuard attributed much of the pattern to AI-assisted development, stating the exposures were consistent regardless of business type because "the humans... do not understand their database's configuration," with site creators using AI coding tools often unaware of the configuration, though the firm stopped short of confirming every affected site was AI-built.1 UpGuard said it notified application owners when its deeper analysis identified significant exposure, and pointed Supabase users toward the platform's security documentation, including its advisors tool and API security guide, to identify and mitigate exposure risk.1
Why it matters: row-level security in Supabase is opt-in rather than default, so a wave of AI-assisted app development without that step has quietly left tens of thousands of production databases readable to anyone who knows to check, making this less a single vendor flaw and more a widespread pattern worth checking your own Supabase projects against.
Sources
- Misconfigured Supabase apps expose data in over 16,000 databases (BleepingComputer)