Supabase · security
UpGuard Finds 16,326 Supabase Databases With Publicly Readable Tables
UpGuard identified 16,326 Supabase databases with publicly readable tables, and more than half had schema indicators of personal information.
Was Supabase itself breached?
Not according to the verified reports. UpGuard describes customer databases exposed through configuration and access-control problems, not an intrusion into Supabase's own infrastructure.
Orbitrum Investor Impact
How much sensitive data was exposed?
UpGuard found 16,326 databases with readable tables among roughly 300,000 domains showing signs of Supabase use. More than half had indicators of personal data, while smaller percentages showed passwords or authentication tokens.
Why does the finding matter for Supabase?
The scale shows that database security configuration remains a material risk as Supabase adoption grows, particularly among apps created with AI coding tools. No revenue, customer-loss or other financial impact from the findings was disclosed.
Have all of the exposed databases been fixed?
Not according to the information published so far. UpGuard said it notified application owners in the significant exposures it individually validated, while Supabase told TechCrunch that it notifies affected customers when security issues are discovered.
What is Supabase changing to reduce future exposure?
Supabase has been moving Data API exposure toward an opt-in model for new tables, with the safer default applying to new projects since May 30, 2026. The company says it plans to enforce the change across existing projects on October 30, 2026.
Sources
- UpGuard — Everything Everywhere: Systemic Data Exposure in Supabase Apps
- TechCrunch — Some Supabase customers are publicly exposing reams of people's data to the web
- Supabase — Breaking Change: Tables not exposed to Data and GraphQL API automatically
Original signal: TechCrunch ↗
See more Orbitrum in Google
Add Orbitrum as a Preferred Source to make our research more likely to appear for you in Google Search.