Security1 publisher2 min readPublished
UpGuard finds more than 16,000 Supabase databases left readable through missing row-level security
UpGuard found more than 16,000 Supabase databases exposing readable tables of personal data, passwords and authentication tokens. It blames row-level security and key settings that each project's owner controls, so every app needs its own fix.
The Watch · Security desk

What happened
- More than half of the exposed databases held personally identifiable information, and a smaller subset held passwords and authentication tokens.
- A U.S. valet service exposed more than 100,000 customer records, including contact details, license plates and visit history.
- An African government consulate exposed records on 25,000 people, including their addresses and emergency housing locations.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure UpGuard notified only owners with significant exposure, and its probe needed just a domain and a table name. Any of the 16,000 that were not told, or have not changed their policies, are open to anyone who repeats it.
- decision UpGuard places the fault in project settings. Anyone buying or inheriting an app built on Supabase therefore has to check its table policies and key use directly, because the vendor has no fix to ship.
- contradiction UpGuard calls AI coding agents the common thread but says its scans cannot show every affected site was AI-built, so the AI-built share of the 16,000 has not been measured.
UpGuard started from a list of about 300,000 domains that showed signs of running on Supabase and asked each one for a table called 'users' [5]. Some requests returned a page of records. Where no 'users' table existed, the response hinted that a table under a different name was open [5]. An attacker would need the same two inputs: a domain and a table name [5]. The more than 16,000 exposed databases [1] come to roughly 5 percent of the domain list, though one domain need not map to one database [1].
Supabase is an open-source backend platform built around PostgreSQL [3]. UpGuard puts the cause in each project's own settings: row-level security policies that were missing or did not work, and misuse of public keys [12]. Closing it means reviewing policies and key handling table by table, and BleepingComputer points users to the platform's security advisors and API security guide for that work [12][17]. The report does not date the scans or name anyone other than UpGuard who has read the tables. UpGuard said it notified owners where deeper analysis showed significant exposure [16].
According to BleepingComputer, AI-assisted development accounts for more than 60% of newly created databases [4]. UpGuard ties the exposure to that trend [14]. "The security settings are invariant to business type because the humans, who know what kind of business they are advertising, do not understand their database's configuration," UpGuard said [13]. "The common thread is that these sites are created by AI coding agents and the humans are unaware of the configuration," the company added [14]. The researchers also said their scans do not establish that every affected site was built with an AI coding agent [15].
A Canadian immigration service had nearly 5,000 user records exposed, including 884 plaintext passwords [8]. That is about 18 percent of the records [2]. A Philippines-based OTP service exposed more than 2,000 users and 100,000 SMS messages, some of them apparently unrelated person-to-person conversations [10]. An India-based adult creator platform exposed identity data, payment accounts and more than 100,000 private messages [9]. Judging by table schemas, UpGuard believes card data sits in a very small set of the exposed data [2].
What to watch
- Whether Supabase changes defaults or advisor warnings for tables left without row-level security after UpGuard's findings.
- Whether the consulate, the immigration service or other described organisations disclose the exposure or find that someone other than UpGuard read the tables.
- A breakdown from UpGuard separating AI-built sites from the rest would test its common-thread claim.