← Blog · · df00tech

Over 16,000 Misconfigured Supabase Databases Found Exposing PII, Passwords, and Auth Tokens

security-news breach

What happened

Researchers reported finding more than 16,000 misconfigured Supabase-backed databases with readable tables exposing personally identifiable information (PII), passwords, and authentication tokens, according to BleepingComputer. Details on the exact misconfiguration mechanism, affected verticals, and scan methodology were not specified in the available reporting.

Why it matters

Supabase is a widely used backend-as-a-service platform (Postgres, auth, storage, and auto-generated APIs) embedded in a large number of consumer and B2B applications. Misconfigurations of this kind typically trace back to overly permissive Row Level Security (RLS) policies or anonymous/public API keys left with broad read access — issues that live in application configuration rather than in Supabase's core infrastructure. Because exposure sits at the app layer, any organization using Supabase (or similar BaaS platforms) for user data, credentials, or session tokens is potentially at risk regardless of Supabase's own security posture.

What defenders should do now

  • Audit RLS policies on every table in your Supabase (or equivalent BaaS) project — default-deny should be the baseline, with explicit policies for each authenticated role.
  • Review which API keys (anon vs. service_role) are exposed client-side and confirm the anon key cannot read tables containing PII, credentials, or tokens.
  • Treat any leaked or long-lived auth tokens as compromised; rotate JWT signing secrets and session tokens if exposure is suspected.
  • Monitor for anomalous read volume or enumeration patterns against your BaaS REST/GraphQL endpoints, especially from unauthenticated or anonymous-role requests.
  • Inventory third-party and internal apps built on BaaS platforms — this class of exposure tends to affect many small, independently deployed apps rather than one central system.

Developing story

This is net-new intel and not tied to a specific CVE or confirmed exploitation campaign; details may evolve as more reporting emerges. See the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.