Security researchers have identified more than 16,000 Supabase databases that were misconfigured, leaving readable tables containing sensitive data publicly accessible. The exposed information includes personally identifiable information (PII), passwords, and authentication tokens, posing significant risks for affected users and organizations.
What happened
The misconfigurations were discovered during a scan of publicly accessible Supabase instances. Researchers noted that the exposed data resulted from improperly set access controls, which allowed unauthorized parties to view or extract information without authentication. The exact number of affected databases—16,000—was confirmed, though the total volume of exposed records remains unclear. Supabase, an open-source Firebase alternative, provides backend-as-a-service solutions, including database management, authentication, and storage.
The source did not specify whether any breaches or unauthorized access incidents have occurred as a result of these misconfigurations. It is also unclear how long the databases have been exposed or whether affected organizations have been notified.
What we don't know yet
Details about the duration of the exposure, the geographic distribution of affected databases, and whether any malicious actors have exploited the misconfigurations are not available. Additionally, the researchers did not disclose whether Supabase has taken steps to address the issue or notify impacted users. Further investigation is needed to determine the full scope of the risk and potential remediation efforts.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 28 Sep 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No recent or in-pipeline article covers this Supabase misconfiguration story.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers this Supabase misconfiguration story.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=615 slug=16-000-supabase-databases-misconfigured-data-exposed quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: The draft states 'The exact number of affected databases—16,000—was confirmed,' but the source only states 'more than 16,000.' The draft should reflect the 'more than' qualifier to avoid overprecision.
- Style compliance: The standfirst uses 'data exposed' while the title uses 'data exposed.' This is redundant
- the standfirst should add new information (e.g., 'Security researchers warn of risks after discovering...').
- Audience relevance and notability: The draft does not explicitly state why this matters to hosting/domains/DNS/email professionals (e.g., Supabase is widely used for backend services, misconfigurations could affect hosted apps). Adding a sentence on operational impact would strengthen relevance.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Rejected library image #28: The only candidate provided (index 0) depicts riot police with shields, which is unrelated to database misconfigurations, Supabase, or data exposure. The alt text mentions 'wordpress security server protection shield,' but the image content does not match the article topic, and the URL slug does not clarify the relevance. No candidate meets the minimum relevance threshold of 70.
- Assigning hero image — Rejected library image #198: The only candidate depicts a generic databank office building with no direct reference to Supabase, misconfigurations, data exposure, or security concepts. The alt text and URL slug do not match the article topic, making it irrelevant for a vulnerabilities-focused news article.
- Assigning hero image — Reused library image reused image #45
- Linking related stories — Linked 4 relations from 321 candidates
- Publishing — Published 16-000-supabase-databases-misconfigured-data-exposed
- Mastodon — Posted https://mstdn.social/@hostingpaper/117350411893711748




Discussion · coming soon
Be the first to join the thread when community discussion launches.