Misconfigured Supabase databases expose sensitive customer data
UpGuard found more than 16,000 publicly readable Supabase databases leaking personal data, passwords, tokens, and some payment details through misconfiguration.
UpGuard found thousands of Supabase-hosted databases making customers’ sensitive information available on the public web through misconfiguration, not a named Supabase vulnerability or confirmed intrusion. DataBreaches.net, citing Zack Whittaker’s TechCrunch report dated 2026-09-26, put the figure at roughly 16,000 databases. BleepingComputer, reporting on 2026-09-28, said UpGuard analyzed about 300,000 domains and found more than 16,000 databases with readable tables. More than half exposed personally identifiable information, and a smaller subset included passwords, authentication tokens, or limited credit-card data. Notable cases included a U.S. valet service with over 100,000 customer records, 884 plaintext passwords among nearly 5,000 records at a Canadian immigration service, and 25,000 records at an African government consulate. Researchers blamed weak row-level security and public-key misuse, often on AI-built sites, and notified owners of significant exposures; the sources disagree only on whether the total is about or more than 16,000.
- UpGuard found publicly exposed Supabase databases; DataBreaches.net said about or roughly 16,000, while BleepingComputer said more than 16,000.
- BleepingComputer reported that UpGuard analyzed about 300,000 domains using Supabase and found readable tables.
- More than half of the exposed databases held personally identifiable information; a smaller subset included passwords, authentication tokens, or limited credit-card data.
- A U.S. valet service exposed over 100,000 customer records.
- A Canadian immigration service had 884 plaintext passwords among nearly 5,000 records.
- An African government consulate had 25,000 exposed records.
- Exposure was attributed to customer misconfiguration, weak row-level security, and public-key misuse, often on AI-built sites, not a named Supabase vulnerability or confirmed intrusion.
- UpGuard notified owners of significant exposures; Zack Whittaker reported the findings via TechCrunch on 2026-09-26.
Coverage timelineoldest first · each row is one article
- · 6d agoSome Supabase customers are publicly exposing reams of people’s data to the web
DataBreaches.net· 74
UpGuard found about 16,000 Supabase databases publicly exposing customers’ sensitive personal data.
- · 4d agoMisconfigured Supabase apps expose data in over 16,000 databases
BleepingComputer· 78
UpGuard found over 16,000 misconfigured Supabase databases exposing PII, passwords, tokens, and some payment data.