#10
BleepingComputer
general
September 28, 2026 at 18:50 UTC
Misconfigured Supabase apps expose data in over 16,000 databases
By Bill Toulas
AI Summary
Researchers discovered more than 16,000 misconfigured Supabase database instances exposing publicly readable tables containing PII, plaintext passwords, and authentication tokens. The widespread misconfiguration stems from developers leaving Supabase's row-level security (RLS) disabled or improperly configured, effectively making sensitive backend data accessible without authentication. Organizations using Supabase for application backends should immediately audit RLS policies and restrict public schema access.
Relevance score: 73.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →