Misconfigured Supabase databases exposing readable tables with sensitive data
Data Leak
Summary
Hide ▲
Show ▼
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with PII, passwords, and authentication tokens. A smaller subset also appears to include credit card data, widening the potential fallout beyond account takeover. The exposure is tied to missing or ineffective row-level security and misuse of public keys, and application owners were notified when significant exposure was identified.
Related Happenings
Moltbook Supabase database exposure
Data Leak
H score45
First: 08.02.2026 09:32
Last: 08.02.2026 09:32
Sources 1
About this happening:
A misconfigured Supabase database exposed Moltbook data, putting API authentication tokens, email addresses, and private messages at risk of unauthorized acces...
Moltbook Supabase database exposure
Data LeakAbout this happening: A misconfigured Supabase database exposed Moltbook data, putting API authentication tokens, email addresses, and private messages at risk of unauthorized acces...
Moltbook AI social platform data leak from exposed Supabase API key
Data Leak
H score32
First: 03.02.2026 12:00
Last: 03.02.2026 12:00
Sources 1
About this happening:
The Moltbook AI social platform suffered a data leak after an exposed Supabase API key gave unauthenticated access to its production database. The exposure put 1...
Moltbook AI social platform data leak from exposed Supabase API key
Data LeakAbout this happening: The Moltbook AI social platform suffered a data leak after an exposed Supabase API key gave unauthenticated access to its production database. The exposure put 1...
Timeline
-
28.09.2026 21:50 2 articles · 2h ago
Misconfigured Supabase databases expose readable tables with sensitive data
Technical Analysis UpdateUpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, authentication tokens, and a small set of possible credit card data. The exposed databases included nearly 5,000 user records at a Canadian immigration service with 884 plaintext passwords, more than 100,000 customer records at a U.S. valet service, more than 100,000 private messages at an India-based adult creator platform, more than 2,000 users and 100,000 SMS messages at a Philippines-based OTP service, and records for 25,000 people at an African government consulate. UpGuard attributed the exposure to missing or ineffective row-level security policies and misuse of public keys, and said it notified application owners when significant exposure was identified.
Show sources
- Misconfigured Supabase apps expose data in over 16,000 databases — www.bleepingcomputer.com — 28.09.2026 21:50
- Misconfigured Supabase apps expose data in over 16,000 databases — www.bleepingcomputer.com — 28.09.2026 21:50