Over 16,000 Supabase Databases Expose Sensitive Data Due to Misconfigurations
A shocking number of databases built on the popular open-source platform Supabase have been found to be exposing sensitive information, including personally identifiable information (PII), passwords, and authentication tokens. Researchers at UpGuard discovered more than 16,000 misconfigured Supabase databases that contain readable tables with sensitive data.
Supabase is an open-source development platform that provides a range of backend services for building and launching apps and websites quickly. Its popularity has grown significantly among developers using artificial intelligence tools to build projects, with AI-assisted development accounting for over 60% of newly created databases. Unfortunately, this trend has also led to a surge in misconfigurations that expose sensitive data.
The researchers analyzed a dataset of around 300,000 domains that showed signs of using Supabase and checked for the presence of a ‘users’ table. While some queries returned a page from the database, others hinted that the ‘users’ table did not exist, but a table with another name was accessible. By examining the table schemas, UpGuard inferred the data types exposed across the set. In more than half of the exposed databases, they found PII, while a smaller subset included passwords and authentication tokens.
The affected databases belong to various organizations across different industries. For instance, a U.S.-based valet service exposed over 100,000 customer records, including contact details, license plates, and visit history. In another case, a Canadian immigration service had nearly 5,000 user records, including 884 plaintext passwords. Other notable findings include sensitive identity, payment accounts, and private messages at an India-based adult creator platform.
UpGuard attributes the exposure to poor application security configurations, including missing or ineffective row-level security policies and misuse of public keys. The researchers emphasize that the security issues are not limited to a particular type of business but rather a result of humans being unaware of their database’s configuration when using AI coding agents.
Supabase users are encouraged to review the platform’s security documentation, including its advisors and API security guide, to identify exposure risks and mitigate them. While UpGuard notified application owners when significant exposure was identified, it is crucial for developers to take proactive steps to secure their databases.
This incident serves as a reminder of the importance of proper configuration and security settings in database management, especially with the increasing use of AI-assisted app development. As we continue to rely on technology to streamline our work processes, it is essential that we also prioritize cybersecurity measures to prevent such misconfigurations from occurring in the future.
To protect yourself and your organization, ensure that you have a robust security plan in place when using Supabase or any other platform. Regularly review your database configurations, implement effective row-level security policies, and monitor your systems for potential vulnerabilities. By taking these steps, you can minimize the risk of data exposure and maintain the trust of your users.
Source: Bleeping Computer — 2026-09-28