UpGuard Finds Supabase Databases Exposing User Data
UpGuard says it found about 16,000 Supabase-hosted databases with some degree of personal data exposed to the public web. The exposed material included names, addresses, phone numbers, user passwords, and in some cases authentication tokens, across apps built on the managed database platform.
The problem is misconfiguration, not a Supabase breach. Developers using hosted or AI-generated apps appear to have left databases reachable from the internet, so the leak surface was the application data itself; once a database is public, the platform can be healthy while the records are not.
That makes the exposure important for teams treating the platform as the security boundary. If a low-code or vibe-coded app stores live customer data there, the lasting risk sits in its access settings and the data it holds, not in any single compromised server.
Misconfigured Supabase apps expose data in over 16,000 databases
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens.