UpGuard Study Finds 16,326 Supabase Databases Exposing Readable Tables

Thousands of databases hosted on the Supabase development platform are exposing sensitive personal information to the public internet, according to cybersecurity firm UpGuard. Researchers identified over 16,000 misconfigured databases leaking data ranging from text messages and vehicle records to government housing files as the AI vibe-coding boom accelerates security oversights.

UpGuard Uncovers 16,326 Exposed Supabase Databases

Security research published on September 25, 2026, by cybersecurity firm UpGuard revealed that thousands of databases hosted on Supabase are openly exposing readable tables to the web. Led by UpGuard’s Director of Research and Insights Greg Pollock, the study identified 16,326 misconfigured databases, marking the largest study of its kind examining the developer platform.

Supabase provides hosted Postgres databases as a service, allowing developers to build web and application back ends quickly. The platform has surged in popularity alongside AI-assisted coding tools, helping Supabase reach a $10 billion valuation as of June 2026, according to UpGuard’s findings. However, that rapid growth has coincided with widespread user misconfigurations that leave sensitive records exposed.

How Researchers Discovered the Vulnerable Databases

To map the exposure without targeting specific AI watermark platforms like Lovable or Replit, researchers focused on standalone websites operating on primary domains. The team utilized BuiltWith technographic fingerprinting and the Chrome UX Report dataset on BigQuery to scan public JavaScript files for Supabase database addresses and API keys.

This methodology gathered approximately 300,000 unique domains exhibiting indicators of Supabase usage. Researchers then queried each target for a common table name, reasoning that users was a frequent default entry point. Because of the massive dataset size, the team evaluated table schemas and deployed an AI model to classify business models rather than reading every individual row.

Read more:  В Приштине в ходе операции изъяли 27 фильтров и 91 килограмм табака - Телеграф

Documented Data Leaks Impacting Real Businesses and Governments

Investigators validated the exposures by examining metadata and schemas from a subset of vulnerable projects. The compromised datasets affected diverse entities worldwide, revealing personal information, login credentials, and operational records.

  • A one-time-passcode service operating via a SIM farm in the Philippines exposed more than 2,000 user accounts with wallet balances alongside over 100,000 SMS messages, including personal ridesharing texts between drivers and passengers.
  • A valet service based in the U.S. Northeast utilized Supabase as its CRM back end, exposing over 100,000 customer records containing phone numbers, email addresses, license plate numbers, and tip histories, along with 665 employee records.
  • An African government consulate in France leaked personal details and physical addresses for 25,000 individuals, including emergency housing locations for vulnerable citizens.
  • A relocation and immigration coaching service for individuals moving to Canada exposed nearly 5,000 user records.

Other exposed projects included private user conversations on an Indian adult streaming site and contact logs for an immigration service. While over half of the vulnerable databases contained personally identifiable information, smaller subsets held authentication tokens, passwords, or indicators of payment processing integration.

Supabase Response and Shared Security Responsibilities

When reached for comment, Supabase Chief Information Security Officer Bil Harmer stated that the company provides secure by default architecture and tools while emphasizing that security remains a shared responsibility between the platform and its users.

UpGuard Study Finds 16,326 Supabase Databases Exposing Readable Tables
Photo: TechCrunch

Harmer added that the company notifies affected customers whenever security issues are identified and noted that platform access controls have been bolstered over the years. Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely, Harmer said.

Продолжение темы

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.