Cybersecurity

More Than 16,000 Supabase Databases Expose Personal Data, Passwords, and Login Tokens

Researchers at UpGuard found that more than 16,000 databases associated with Supabase allowed access to readable tables, containing personal data in more than half of cases, with passwords and authentication tokens present in a smaller group. The flaw is linked to incorrect security settings, including row-level security policies and improperly used public keys.

2026-09-28
3 min read
3 views
certi.news Editorial Team
More Than 16,000 Supabase Databases Expose Personal Data, Passwords, and Login Tokens

An analysis conducted by cybersecurity risk management company UpGuard found that more than 16,000 databases using Supabase were exposed because of incorrect settings, allowing tables containing personal data, credential information, and authentication tokens to be read. The company says a very small proportion of the exposed data may include credit card information, based on an analysis of table schemas.

Supabase provides an open-source platform built around PostgreSQL and offers backend services that help build and launch applications and websites quickly. The platform has grown in popularity among developers who use artificial intelligence tools, with UpGuard saying that AI-assisted development accounts for more than 60% of newly created databases, while stressing that the scans do not prove that all affected sites were built using AI coding agents.

Scope of the Data Revealed in the Scan

UpGuard researchers analyzed a set of approximately 300,000 domains that appeared to show signs of using Supabase and searched for tables named users. In some cases, the queries returned a page from the database, while in other cases they showed that a table with a different name was accessible. Based on the table schemas, the researchers inferred the types of data that could be accessed.

More than half of the exposed databases contained personally identifiable information, while a smaller group included passwords and authentication tokens. Examples cited by the company include:

  • A U.S. parking service exposed more than 100,000 customer records, including contact details, vehicle license plates, and visit history.
  • A Canadian immigration service exposed nearly 5,000 user records, including 884 plaintext passwords.
  • An Indian platform for adult content creators exposed identity and payment-account data, as well as more than 100,000 private messages.
  • A Philippine OTP service exposed data belonging to more than 2,000 users and 100,000 SMS messages, including personal communications that appear to be unrelated to the service.
  • An African government consulate exposed records concerning 25,000 people, including addresses and emergency residential locations.

What Does the Flaw Expose?

UpGuard attributed the exposures to weak application security settings, including missing or ineffective row-level security policies, as well as the misuse of public keys. The company believes that the type of business does not explain the problem; the common factor is that application developers or operators did not configure the database in accordance with the sensitivity of the data stored in it.

These findings indicate that the speed of building applications, whether with or without the help of artificial intelligence, does not replace reviewing access permissions and database policies. However, the source provides no evidence identifying the proportion of sites actually created by AI, so the use of these tools cannot be considered a proven cause of every exposure.

What Should Supabase Users Review?

UpGuard said it notified application owners when its in-depth analysis revealed a significant exposure. It also urged Supabase users to review the platform’s security documentation, including the Advisor tools and the API security guide, to look for and address exposure risks. Details specific to each database, such as how long it remained exposed and how many times it was accessed, are not mentioned in the source material.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news