Misconfigured Supabase Apps Expose Data in Over 16,000 Databases
Researchers identify widespread exposure of personally identifiable information and authentication tokens due to default allow rules

Key Takeaways
- Over 16,000 Supabase databases were found with public read access due to default allow rules.
- Exposed data includes personally identifiable information, passwords, and authentication tokens.
- The exposure is attributed to default security settings that permit unrestricted table reads.
- Supabase has updated its documentation to stress the importance of configuring row-level security policies.
- Organizations using Supabase must review and enforce explicit access controls for production environments.
Quick answers
- What happened?
- Security researchers have identified more than 16,000 Supabase-backed applications with publicly accessible databases. The exposure stems from default allow rules that permit unrestricted read access to tables containing personally identifiable information, passwords, and authentication tokens. The findings highlight the risk of misconfigured backend-as-a-service platforms when security defaults are not adjusted for production use.
- Which products are affected?
- Supabase Platform
- What should defenders do?
- Enable and configure row-level security policies to restrict table access. Review Supabase security documentation and apply explicit access controls for all production databases.
Security researchers have discovered that over 16,000 Supabase-powered applications are exposing database contents due to misconfigurations. The issue arises from Supabase's default security settings, which allow public read access to database tables. This has resulted in readable tables containing personally identifiable information, plaintext passwords, and authentication tokens being accessible without authentication. The researchers reported the findings to Supabase, which has since updated its documentation to emphasize the need for explicit row-level security policies. The incident serves as a reminder of the shared responsibility model between platform defaults and and customer configuration for production deployments.
Security Details
Default allow rules in Supabase projects permit public read access to database tables if row-level security policies are not explicitly defined.
Affected products
Supabase Platform
Mitigation
Enable and configure row-level security policies to restrict table access. Review Supabase security documentation and apply explicit access controls for all production databases.
Sources
BleepingComputer
Misconfigured Supabase apps expose data in over 16,000 databases
Sep 28, 2026 · 18:50
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

Dark Reading Publishes Step-by-Step Guide to Building SASE Frameworks for Edge Security
Dark Reading has released a guide detailing the construction of a Secure Access Service Edge (SASE) framework. The article focuses on helping organizations rethink security governance to protect edge computing environments, providing a step-by-step architectural path rather than addressing a specific vulnerability or threat.



