UpGuard (24 Sep) / Bleeping 28 Sep: >16,000 misconfigured Supabase apps expose PII, passwords, auth tokens
UpGuard research by Greg Pollock (“Everything Everywhere: Systemic Data Exposure in Supabase Apps”; published 24 September 2026; BleepingComputer amplified 28 Sep) documents systemic exposure across more than 16,000 misconfigured Supabase (PostgreSQL) backends. From ~300,000 domains showing Supabase use, researchers probed for readable users tables / schemas. More than half of exposed databases held PII; a smaller subset included passwords or authentication tokens; a very small set had plausible credit-card fields. Example exposures cited: US valet CRM >100k customer records (contacts, plates, visit history); Canadian immigration service ~5k users incl. 884 plaintext passwords; India-based adult creator platform with identity/payment accounts and >100k private messages; Philippines OTP service >2k users / ~100k SMS; African government consulate ~25k people with addresses and emergency housing locations. Root cause: missing or ineffective row-level security and public-key misuse — often on AI-assisted (“vibe coded”) apps where humans do not understand DB config; Supabase RLS-by-default in Table Editor UI does not cover API/programmatic table creation used by coding agents. UpGuard notified owners of significant findings. Not a Supabase platform breach — customer misconfiguration. Watchlist: UpGuard primary. Primary: UpGuard; wire: BleepingComputer 28 Sep.
- Product
- Supabase (hosted PostgreSQL / client apps) — customer row-level security / API key configuration
- Versions
- n/a (misconfiguration class across many apps; not a single product CVE). RLS default for Table Editor UI tables does not apply to API-created tables used by many AI coding agents.
- Exploited in Australia?
- unknown
- Patch to
- Enable and correctly configure Supabase row-level security on every table; never expose service-role keys client-side; run Supabase security advisors; rotate exposed passwords/tokens; review AI-generated schemas before production; treat any historically public project URL as potentially scraped.
Primary: UpGuard — Everything Everywhere: Systemic Data Exposure in Supabase Apps (24 Sep 2026) · Vendor: Supabase docs — Securing your API / advisors · BleepingComputer — Over 16,000 Supabase databases expose PII (28 Sep 2026)
