News / Cybersecurity
16,000 Supabase Databases Exposed: Sensitive Data Accessible Due to Flawed Configurations Published on 29 September 2026 by Christ-loisele (3 min read)
Researchers from UpGuard reveal that 16,000 Supabase databases, used by companies and government agencies, leave critical data accessible due to poorly configured security settings. Among the affected: an African consulate, Canadian immigration services, and Indian platforms.
A widespread vulnerability linked to the growing use of AI in development
UpGuard researchers identified over 16,000 exposed Supabase databases due to flawed security configurations, according to BleepingComputer . The Supabase platform, built around PostgreSQL, is widely adopted for its accessibility, particularly thanks to AI-driven automation. According to UpGuard, over 60% of new databases created on Supabase are generated via AI-assisted tools, increasing the risk of configuration errors.
Data exposure primarily stems from the absence or ineffectiveness of row-level security policies (Row Level Security, RLS). Tables containing personal information, plaintext passwords, authentication tokens, or payment details were accessible via Supabase’s REST API, as explained in dev.to . Queries using only a public key are evaluated under PostgreSQL’s anon role, bypassing user authentication checks.
Security configurations remain unchanged regardless of activity type because users, familiar with their industry, often overlook their database settings.
Illustration: Lawing Tech
Diverse sectors affected, including government agencies and sensitive services
Exposed data spans critical sectors. An American valet service leaked over 100,000 customer records, including license plates and visit histories. A Canadian immigration service exposed nearly 5,000 files, including 884 plaintext passwords, according to BleepingComputer . In Asia, an Indian platform for adult content creators had exposed identities, payment accounts, and over 100,000 private messages, while a Philippine OTP messaging service lost data on 2,000 users and 100,000 SMS.
In Africa, a government consulate exposed data on 25,000 individuals, including addresses and emergency shelter locations. These cases highlight the vulnerability of public and private infrastructures when security configurations fail to meet real needs.
What this means here: increased risks for African businesses and government agencies
For businesses and government agencies in Benin and West Africa, this vulnerability underscores the urgency of adopting rigorous security practices, especially when automated development tools are used. The absence of row-level security policies (RLS) or their poor configuration could expose sensitive data, such as citizens’ personal information or financial transactions, to cyberattacks or accidental leaks.
Public administrations, in particular, should audit their databases to verify that security mechanisms are activated and train their teams in best practices. Companies using Supabase or similar solutions should also limit access to API keys and prioritize minimal access roles, as recommended by Supabase itself. Increased vigilance over configurations could prevent incidents comparable to those documented.
How to detect and correct vulnerabilities?
UpGuard and Supabase experts highlight that vulnerabilities often stem from a lack of understanding of security configurations. Administrators should ensure that RLS policies are enabled on tables exposed via the API and restrict permissions according to the principle of least privilege. Dev.to also recommends cross-referencing API request logs with database-side audits to detect any suspicious activity.
Supabase recommends defining RLS policies based on membership and authentication attributes, and avoiding the use of service_role keys in production unless strictly necessary. For organizations using AI-assisted development tools, a human review of configurations remains essential.
Sources