<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/misconfigured-supabase-apps-expose-data-in-over-16-000-databases-kpjoa0fjs" -->

---
title: Misconfigured Supabase apps expose data in over 16,000...
description: Security researchers at UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables containing personally identifiable...
canonical: https://daily.dev/posts/misconfigured-supabase-apps-expose-data-in-over-16-000-databases-kpjoa0fjs
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Misconfigured Supabase apps expose data in over 16,000 databases | daily.dev
og:description: Security researchers at UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables containing personally identifiable...
og:url: https://daily.dev/posts/misconfigured-supabase-apps-expose-data-in-over-16-000-databases-kpjoa0fjs
og:image: https://api.daily.dev/og/posts/kpjoA0fJs.png
og:image:alt: Misconfigured Supabase apps expose data in over 16,000 databases
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Misconfigured Supabase apps expose data in over 16,000 databases

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Security researchers at UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables containing personally identifiable information, and in some cases passwords, authentication tokens, and a small amount of credit card data. Analysis of roughly 300,000 domains using Supabase revealed missing or ineffective row-level security policies and misused public keys as the main causes. Notable exposures included a U.S. valet service with over 100,000 customer records, a Canadian immigration service with nearly 5,000 records including 884 plaintext passwords, an India-based adult platform, a Philippines-based OTP service, and an African government consulate. UpGuard links the pattern to sites built by AI coding agents, where developers were unaware of their database's security configuration, though it does not claim every exposed site was AI-built.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases>

## Questions this post answers

### Why are so many Supabase databases exposing user data publicly?

Researchers at UpGuard found over 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, and in some cases passwords or authentication tokens. The root causes are missing or ineffective row-level security policies and misuse of public keys, often because developers using AI coding agents to build the apps did not understand their database's security configuration.

_Anyone shipping a Supabase backend can follow database security fixes and configuration guidance on daily.dev._

### Does using AI coding agents increase the risk of database misconfiguration in Supabase apps?

Yes, sites built with AI coding agents show a strong pattern of exposure because the humans behind them are often unaware of the underlying database configuration, according to UpGuard's research. AI-assisted development now accounts for more than 60% of newly created Supabase databases, though researchers note their scans cannot confirm every affected site was AI-built.

_Developers weighing AI-assisted backend tooling against security risk can track findings like this on daily.dev._

## Similar posts on daily.dev

- [Supaguard : Scan, Detect & Protect Your Supabase Data](https://daily.dev/posts/supaguard-scan-detect-protect-your-supabase-data-6gz35nc3a) · Product Hunt · 0 upvotes · 0 comments
- [The Default SaaS Starter Pack Is the Least Secure Way to Ship an App](https://daily.dev/posts/the-default-saas-starter-pack-is-the-least-secure-way-to-ship-an-app-w6mw2xewx) · Medium · 0 upvotes · 0 comments
- [AI-built app on Lovable exposed 18K users, researcher claims](https://daily.dev/posts/ai-built-app-on-lovable-exposed-18k-users-researcher-claims-wdpsjqwku) · The Register · 0 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#postgresql](https://daily.dev/tags/postgresql), [#supabase](https://daily.dev/tags/supabase)

[View this post on daily.dev](https://daily.dev/posts/misconfigured-supabase-apps-expose-data-in-over-16-000-databases-kpjoa0fjs)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Misconfigured Supabase apps expose data in over 16,000 databases","url":"https://daily.dev/posts/misconfigured-supabase-apps-expose-data-in-over-16-000-databases-kpjoa0fjs","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/misconfigured-supabase-apps-expose-data-in-over-16-000-databases-kpjoa0fjs"},"datePublished":"2026-09-28T18:52:30.494Z","dateModified":"2026-09-28T19:13:55.842Z","description":"Security researchers at UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables containing personally identifiable...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3d433323e3df5720669e9f52a202e3a6?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3d433323e3df5720669e9f52a202e3a6?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/misconfigured-supabase-apps-expose-data-in-over-16-000-databases-kpjoa0fjs","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,postgresql,supabase","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Misconfigured Supabase apps expose data in over 16,000 databases"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/misconfigured-supabase-apps-expose-data-in-over-16-000-databases-kpjoa0fjs#faq","mainEntity":[{"@type":"Question","name":"Why are so many Supabase databases exposing user data publicly?","acceptedAnswer":{"@type":"Answer","text":"Researchers at UpGuard found over 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, and in some cases passwords or authentication tokens. The root causes are missing or ineffective row-level security policies and misuse of public keys, often because developers using AI coding agents to build the apps did not understand their database's security configuration. Anyone shipping a Supabase backend can follow database security fixes and configuration guidance on daily.dev."}},{"@type":"Question","name":"Does using AI coding agents increase the risk of database misconfiguration in Supabase apps?","acceptedAnswer":{"@type":"Answer","text":"Yes, sites built with AI coding agents show a strong pattern of exposure because the humans behind them are often unaware of the underlying database configuration, according to UpGuard's research. AI-assisted development now accounts for more than 60% of newly created Supabase databases, though researchers note their scans cannot confirm every affected site was AI-built. Developers weighing AI-assisted backend tooling against security risk can track findings like this on daily.dev."}}]}
```

