CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Over 16,000 Supabase databases expose PII, passwords, auth tokens

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8764

As cited

Copy frozen at (site build).

cloud saas

Over 16,000 Supabase databases expose PII, passwords, auth tokens

Researchers discovered over 16,000 misconfigured Supabase databases with publicly readable tables containing personally identifiable information, passwords, and authentication tokens. The exposure stemmed from insecure default configurations or inadequate access controls on the backend-as-a-service platform.

Why it matters: Development teams using Supabase should immediately audit their database configurations and access policies to ensure sensitive data is not exposed; customers of affected services may have credentials and personal data at risk.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary