A cybersecurity firm UpGuard has found that thousands of databases hosted on Supabase can expose private information to the public internet. According to the research, approximately 16,000 databases hosted on the platform were able to be accessed by individuals through some form of personal data. The findings indicate that misconfigured databases and applications are a recurring security issue.
Data storage and operations are widely facilitated by Suprabase for web and mobile applications, while the increasing use of artificial intelligence-assisted vibration coding has allowed developers with limited security expertise to create and deploy applications more easily. Among the exposed databases, UpGuard found names, addresses, telephone numbers, and passwords that were publicly accessible. A smaller number also contained authentication tokens.
Various services and projects were connected to the exposed information, demonstrating that the problem is not limited to one type of application or industry. Datasets examined by researchers include private conversations provided by an Indian adult streaming platform, thousands of license plates owned by a valet service in the United States, as well as contacts for immigration and relocation services in the United States.
Another exposed database reportedly served as a gateway to intercepting text messages via a virtual SIM farm. As UpGuard discovered, the database was linked to a consulate of the African government in France. By using these systems, online account holders can receive one-time verification codes, but when their data is left accessible via the internet, additional risks may be incurred.
It is evident that the problem extends beyond isolated incidents; earlier investigations had also identified the public exposure of Supabase databases belonging to startups and widely used applications. UpGuard identified a large number of data sets that were located in the United States; however, the researchers indicated that the exposed databases were part of a global problem.
An analysis performed by UpGuard identified 16,326 databases with Supabase tables that were publicly accessible. Approximately half of the databases contained personally identifiable information, and a smaller number contained passwords, authentication tokens, and payment card information in rare cases. The researchers also tested a sample of the databases to confirm that some of the exposed records contained information that was accurate.
There has been prior documentation of this problem.
In 2025, research discovered misconfigured Supabase databases connected to AI-assisted development platforms, and further investigation identified access controls and public key handling issues. The latest findings suggest that similar configuration errors remain widespread as more applications are constructed using AI coding tools for building and deploying.
Although Suprabase has implemented additional security safeguards, researchers noted that they are not necessarily applied automatically when databases are built using programming platforms. Nevertheless, proper configuration remains the only way to prevent unauthorized access to stored data. In addition, the findings highlight the differences between securing the backend of an application and building it.
In contrast to AI-assisted development producing a working application rapidly, security settings around database access remain dependent upon decisions made during deployment. Consequently, access controls that are incorrectly configured can expose a database accessible through a given application when they are incorrectly configured.
Supabase, on the other hand, stated that its projects are automatically secure and that database security is a shared responsibility between all parties.
Managing Director of Information Security Bil Harmer stated that customers control how their projects are configured, while Supabase provides security defaults and tools and informs customers as soon as security threats are identified. The company has also implemented security-related changes to its platform over the years.
The scope identified in the latest research, however, indicates that customer-side database configuration remains a critical part of the security equation, given that Supabase continues to be used for applications developed using artificial intelligence-assisted development tools. This study demonstrates that poorly configured cloud databases pose security risks, particularly as AI-assisted development continues to accelerate application deployments.
Maintaining strict access controls and configuring databases carefully remain essential to prevent the public from having access to sensitive information.