Over 16,000 Supabase Databases Expose Sensitive Data Due to Misconfigurations
A recent analysis by cybersecurity researchers at UpGuard has uncovered a staggering number of misconfigured Supabase databases exposing sensitive data. The investigation found that more than 16,000 databases were accessible without proper security measures in place, putting the personal identifiable information (PII), passwords, and authentication tokens of millions of individuals at risk.
Supabase is an open-source development platform built around PostgreSQL, used by developers to build and launch apps and websites quickly. Its popularity has grown significantly, with AI-assisted development accounting for over 60% of newly created databases. The service provides a range of backend services that enable rapid application development, but its ease of use may have contributed to the widespread misconfigurations.
The researchers analyzed a dataset of around 300,000 domains that showed signs of using Supabase and checked for a ‘users’ table. While some queries returned a page from the database, others hinted that the ‘users’ table did not exist, but a table with another name was accessible. By examining the table schemas, UpGuard inferred the data types exposed across the set. In over half of the exposed databases, they found PII, while a smaller subset included passwords and authentication tokens.
The affected organizations span various sectors and geographies, including a U.S. valet service that exposed more than 100,000 customer records, a Canadian immigration service that exposed nearly 5,000 user records, including plaintext passwords, and an India-based adult creator platform that exposed sensitive identity information, payment accounts, and private messages.
The researchers attribute the exposure to poor application security configurations, including missing or ineffective row-level security policies and misuse of public keys. They note that the security issues are not limited to a particular type of business and that humans often lack understanding of their database’s configuration, particularly when AI coding agents are involved in development.
To mitigate these risks, Supabase users are encouraged to review the platform’s security documentation, including its advisors and API security guide, to identify exposure risks and take corrective action. This incident serves as a stark reminder of the importance of proper security configurations, especially with the increasing use of AI-assisted app development.
As more organizations adopt AI-powered development tools, it is crucial for developers and IT professionals to understand the associated security implications. By prioritizing security from the outset, we can minimize the risk of misconfigurations and protect sensitive data.
Source: Bleeping Computer — 2026-09-28