Eigen RadarAI
Analysis

UpGuard finds thousands of readable Supabase databases

UpGuard says about 16,000 Supabase customer databases exposed some personal information. Table permissions and weak row-level security left records reachable outside the intended user group, a risk for applications assembled quickly with AI coding tools. Supabase says its projects are secure by default and customers control the configuration. The finding concerns affected customer projects, not every database on the platform. The figure shows the reported scale; the personal data reachable in each project depend on its settings.

Artificial Intelligence··Evening
Data trays visible inside a server cabinet with its glass access door left ajar.

Thousands of tables could be queried

Cybersecurity firm UpGuard counted about 16,000 customer databases with some personal information reachable on Supabase. Its scan was published on 25 September. The exposed material it described included names, addresses and telephone numbers, and, in fewer cases, passwords or authentication tokens. These were databases belonging to customers using Supabase, the platform that packages database and application services; the count is not a claim that Supabase’s own central database was opened.[1]

Access rules left some records readable

The issue turns on who can query a table, not on an attacker breaking encryption. UpGuard linked the exposure to absent or weak row-level security and to database tables that remained reachable through public application interfaces. Such settings matter particularly when an AI coding agent creates tables programmatically: the app can work while access checks remain incomplete. The count comes from UpGuard’s scan of customer projects. The scan therefore identifies exposed projects, without proving that every Supabase customer has the same configuration.[1]

Supabase assigns configuration to customers

Supabase chief information security officer Bil Harmer said the company had not seen UpGuard’s research when asked and that its projects are secure by default. He said customers control their own configurations and that affected customers are notified. UpGuard’s examples included records from a US valet service and an immigration service, showing that the exposed fields vary by project. The question for each owner is whether its own table permissions allow people outside the intended user group to read records; the reported total does not describe a single shared breach mechanism affecting all projects.[1]

References

  1. News sourceTechCrunchUpGuard counts about 16,000 exposed Supabase databases↩1↩2↩3