Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Supabase data exposure: UpGuard finds 16,326 databases with publicly readable tables

UpGuard says missing row-level security and misused public keys left thousands of Supabase-backed apps leaking names, messages, passwords and tokens.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1UpGuard found 16,326 Supabase databases with publicly readable tables after checking about 300,000 domains that showed signs of using Supabase.
  • 2Over half showed signs of personal data; a smaller share held passwords or authentication tokens, UpGuard said.
  • 3UpGuard says tables created through the API, as AI coding agents do, do not get row-level security by default.

The news

Security firm UpGuard said on September 25, 2026 that it found 16,326 Supabase databases with tables anyone on the internet could read, a Supabase data exposure it tied to missing access rules and misused public keys in apps built on the backend service.

Supabase provides developers with a hosted Postgres database and related services, a category known as backend-as-a-service. In a report written by Greg Pollock, UpGuard's director of research and insights, the firm said it identified about 300,000 unique domains showing signs of Supabase use, using BuiltWith technology fingerprinting and the Chrome UX Report dataset. It then queried each one for a table named “users,” reasoning that it is a common table name.

Of the 16,326 databases with publicly readable tables, more than half had indicators of personally identifiable information, UpGuard said. Fewer held passwords or authentication tokens, according to the report, and only a handful appeared to contain credit card data.

UpGuard described several cases. It said a U.S. valet service exposed records on more than 100,000 customers, including contact details and visit history, plus 665 staff records. A Canadian immigration service exposed about 5,000 records, 884 of them with plaintext passwords. An India-based content platform exposed data on 65,467 users, including personal and financial details and more than 100,000 private messages. An African government consulate exposed physical addresses for 25,000 users, and a Philippines text-message verification service exposed more than 100,000 SMS messages. UpGuard said it notified application owners where it found a significant exposure.

According to UpGuard, the exposures stem from how apps were configured. Row-level security (RLS), the Postgres feature that limits which rows a user can read, was missing or ineffective, and public keys meant to sit in client-side code were treated as if they were secret credentials. UpGuard said that after a developer reported widespread misconfigured Supabase databases built with the Lovable coding platform in March 2025, Supabase changed its Table Editor so tables made there have RLS switched on by default. That safeguard does not cover tables created through the API, the report said, and the API is the route AI coding agents use to work with Supabase.

Supabase's chief information security officer, Bil Harmer, told TechCrunch that projects are secure by default and described security as a shared responsibility between the company and its customers. TechCrunch reported that Supabase reached a $10 billion valuation earlier in 2026.

The numbers

Databases with publicly readable tables
16,326
Domains checked for Supabase use
About 300,000
Exposed databases with signs of personal data
More than half
Plaintext passwords at one Canadian immigration service
884
Customers exposed at one U.S. valet service
More than 100,000
Supabase valuation (2026, per TechCrunch)
$10 billion

Why CEOs should care

For CISOs, the risk sits outside the usual review process. Product teams, marketing groups and individual employees can now stand up a working app in days, sometimes with an AI coding agent writing the database code. UpGuard's finding that API-created tables do not get row-level security by default means those projects can go live with customer data readable by anyone who finds the public key in the app's code. Ask for an inventory of every Supabase project tied to company accounts or domains, and require an RLS check on every table before launch.

For buyers and procurement teams, many small software vendors build on services like Supabase. Add a question to vendor security reviews: which backend services hold our data, and how do you verify access controls on every table? A vendor's clean penetration test from last year says little about tables added since.

For general counsel and boards, a publicly readable table holding personal data can raise breach notification questions, depending on the jurisdiction and whether anyone accessed it. Supabase's framing of security as a shared responsibility signals that it expects customers to own their access rules. Boards should ask whether anyone at the company is accountable for apps built outside central IT.

The bigger picture

UpGuard compared the pattern to Amazon's (AMZN) S3 storage service, whose early defaults made it easy to read and write data and, the firm said, led to thousands of data leaks. UpGuard argued that a platform as widely used and as easy to misconfigure as Supabase should rebalance its defaults, as S3 and GitHub have done. AI coding tools speed up the same cycle: they make it easy to create databases and tables quickly, and the security settings depend on how the tool creates them. Until secure defaults cover every path, including the API that agents use, the checks have to happen on the customer side.

What’s next

Watch whether Supabase extends default row-level security to tables created through its API, and whether AI coding tools begin enabling RLS automatically when they build Supabase-backed apps. Companies can act now by scanning their own Supabase projects for tables readable with the public key.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

SupabaseUpGuarddata exposureAI coding agents

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.