Skip to content
Security & Trust

16,326 Supabase databases exposed readable tables, UpGuard finds

The person who accepts an AI agent's database setup may never see the setting that decides who can read it.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
16,326 Supabase databases exposed readable tables, UpGuard finds

AI-generated image for WebPulse. About our images

Key finding

Databases exposing readable tables: 16,326 (Source: UpGuard Research, as reported by BleepingComputer (September 28, 2026))

The setting nobody chose

Security teams have long assumed that someone, somewhere, decided who can read a given database. UpGuard Research's new Supabase study suggests otherwise. UpGuard argues the decision was made by a default or an AI coding agent, and that the humans behind the sites were unaware of the configuration, though its scans do not show which sites were agent-built.

This is the publication's reading of the findings: the risk did not disappear when software became easier to build, it may have moved to a setting that no human is looking at. UpGuard describes the mechanism this way: security settings do not vary with business type "because the humans, who know what kind of business they are advertising, do not understand their database's configuration."

What UpGuard measured

UpGuard did not start from vibe-coding platforms such as Lovable or Replit, as earlier studies had. It looked for standalone sites on their own primary domains, which it argues captures sites built with agents like Claude Code and Codex. It fingerprinted Supabase use through key names and database addresses in public JavaScript files, drawing on BuiltWith and the Chrome UX Report dataset on BigQuery.

That produced roughly 300,000 unique domains with signs of Supabase usage. UpGuard queried each for a "users" table. Across the set, it identified 16,326 databases exposing readable tables. Rather than read every row, the researchers used table schemas to judge what kinds of data were exposed. Over half of the databases showed indicators of some personal information, and a smaller share showed passwords or authentication tokens.

16,326
Databases exposing readable tables
Source: UpGuard Research, as reported by BleepingComputer (September 28, 2026)
~300,000
Unique domains with Supabase indicators queried
Source: UpGuard Research (September 2026)

What sat behind the open tables

BleepingComputer, reporting on the study, listed cases from UpGuard's findings. In the U.S., a valet operator's database sat open with over 100,000 customer entries, tying people to their vehicle plates and their visits. A Canadian immigration service had nearly 5,000 user records readable, 884 of which held passwords in plain text. A consulate run by an African government left data on 25,000 people readable, with home addresses and the locations of emergency housing among the fields.

UpGuard attributes the exposures to missing or ineffective row-level security (RLS) policies and to public keys used as if they were secret. Supabase has since made RLS the default for tables built in its Table Editor interface. Tables created in code through the API, the route coding agents use to work with Supabase, do not get RLS switched on automatically, according to UpGuard.

An old pattern with a new author

UpGuard places this in a lineage. Amazon S3's defaults made reading and writing data easy and led to thousands of leaks. GitHub's public-by-default model led to exposed credentials and personal information. In each case, convenience won adoption and misconfiguration followed at scale. UpGuard's view is that the new element is who applies the default: an AI coding agent working for someone with little software engineering experience.

Two caveats bound the findings. UpGuard concedes that probing for a "users" table tilts the sample toward personal data. And, per BleepingComputer, the researchers cautioned that their scans cannot show that every exposed site was built with an AI coding agent. The study shows a large exposure and a plausible common cause, not a measured share attributable to AI tools.

1.5 million API tokens
Exposed Moltbook data (Wiz, February 2026)
Source: Wiz, cited in UpGuard Research (September 2026)

Questions to put to your team

Start with vendors and internal builds. Which customer-facing services, including marketing microsites and pilots, run on Supabase or a similar backend-as-a-service? Who owns the database configuration, and can they show you the RLS policies rather than describe them?

Then look at process. When an engineer or contractor uses an AI agent to create tables, does anyone review what the agent left open? Are public keys separated from secret keys in shipped client code? UpGuard points Supabase users to the platform's security advisors and API security guide as places to check exposure.

The lesson is a familiar one in a new place. A convenient default is a decision made on your behalf, and someone in your organization has to own it.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: UpGuard.

Share this insight