Thousands of Supabase Databases Found Openly Exposing Personal Data
Security researchers have uncovered a widespread issue affecting more than 16,000 Supabase instances, where misconfigured access controls left entire tables readable to anyone on the internet. The exposed data includes personally identifiable information, password hashes and authentication tokens, raising concerns about potential credential theft and account compromise.
Supabase, an open‑source backend‑as‑a‑service platform built on PostgreSQL, has gained popularity among developers for its rapid deployment of APIs, authentication, and real‑time features. While the service provides powerful tools for building modern applications, it also relies on developers to configure database permissions correctly. In many cases, default settings permit read access unless explicitly restricted, a nuance that can be overlooked during fast‑paced development cycles.
The investigative scan conducted by the research team targeted publicly reachable Supabase endpoints and identified databases where tables containing sensitive user details were accessible without any form of authentication. Among the data types discovered were email addresses, usernames, hashed passwords, API keys and session tokens. Because the information was stored in plain tables, attackers could retrieve it in bulk using simple HTTP requests.
Exposing such data creates a fertile ground for malicious actors. Password hashes, when paired with publicly available email addresses, can be subjected to cracking attempts, while authentication tokens may allow direct access to user accounts on the associated applications. The incident underscores a broader trend of cloud‑based misconfigurations, where convenience and speed sometimes eclipse rigorous security reviews.
Following the disclosure, Supabase released a public advisory urging developers to audit their database policies, enable row‑level security, and rotate any credentials that may have been compromised. The company also highlighted built‑in tools for managing access controls and recommended that users employ automated scanning solutions to detect inadvertently exposed instances. Security experts advise organizations to regularly review permission settings and to adopt a principle‑of‑least‑privilege approach when configuring backend services.
The findings arrive at a time when serverless and backend‑as‑a‑service platforms are increasingly adopted by startups and small teams lacking dedicated security staff. As regulators and privacy watchdogs tighten scrutiny over data breaches, the incident serves as a reminder that even modern development stacks are vulnerable without proper configuration. Users of affected applications are encouraged to monitor account activity, enable multi‑factor authentication where possible, and be prepared to reset passwords in case of unauthorized access.
Comments (0)
Be the first to comment.
Join the discussion