Home / Sep 30, 2026 / Story
0
#10 BleepingComputer general September 28, 2026 at 18:50 UTC

Misconfigured Supabase apps expose data in over 16,000 databases

By Bill Toulas

AI Summary

Researchers discovered more than 16,000 misconfigured Supabase database instances exposing publicly readable tables containing PII, plaintext passwords, and authentication tokens. The widespread misconfiguration stems from developers leaving Supabase's row-level security (RLS) disabled or improperly configured, effectively making sensitive backend data accessible without authentication. Organizations using Supabase for application backends should immediately audit RLS policies and restrict public schema access.

Relevance score: 73.0/100

# More from September 30