Research Finds Data Exposure Across More Than 16,000 Supabase Databases

Security researchers analyzing AI-assisted vulnerability discovery and exploit trends

UpGuard researchers say they identified more than 16,000 Supabase databases with publicly readable tables that exposed personal information, passwords, authentication tokens or other application data. The findings point to recurring configuration failures in projects built on the popular backend platform rather than a single breach of Supabase itself.

Client-side keys can expose weak access controls

Supabase applications commonly include a public anonymous key so browsers and mobile clients can reach approved data. Security depends on row-level security policies and database permissions limiting what that key can retrieve. The research found applications where those controls were absent or incomplete, allowing unauthenticated queries to return sensitive records.

UpGuard linked the scale of exposure partly to rapid application development and AI-assisted coding, where teams may deploy a functional backend before validating authorization rules. The affected applications covered multiple sectors and data types, so risk must be assessed project by project.

Testing should use an external attacker view

Developers should inventory Supabase projects, enable row-level security and test every exposed table with the same anonymous credentials shipped to clients. Secrets should never be stored in readable application tables, and exposed tokens must be revoked rather than merely hidden. SectechMedia follows cloud and application risk in its cybersecurity coverage.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *