Breaches · 7h ago
UpGuard says it found about 16,000 Supabase-hosted databases with some degree of personal data exposed to the public web. The exposed material included names, addresses, phone numbers, user passwords, and in some cases authentication tokens, across apps built on the managed database platform.
The problem is misconfiguration, not a Supabase breach. Developers using hosted or AI-generated apps appear to have left databases reachable from the internet, so the leak surface was the application data itself; once a database is public, the platform can be healthy while the records are not.
That makes the exposure important for teams treating the platform as the security boundary. If a low-code or vibe-coded app stores live customer data there, the lasting risk sits in its access settings and the data it holds, not in any single compromised server.
2 sources covering this story
Misconfigured Supabase apps expose data in over 16,000 databases
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens.
Some Supabase customers are publicly exposing reams of people's data to the web | TechCrunch
The findings highlight how AI-generated and vibe-coded apps can spill and expose users' data when not configured or secured properly.
Part of the PlainSec briefing for 2026-09-28