{"id":2070,"date":"2026-09-29T12:08:53","date_gmt":"2026-09-29T06:38:53","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=2070"},"modified":"2026-10-01T10:32:36","modified_gmt":"2026-10-01T05:02:36","slug":"supabase-data-exposure-16000-databases-rls","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/","title":{"rendered":"Supabase Data Exposure: How 16,326 Databases Became Readable"},"content":{"rendered":"<p>The Supabase data exposure documented by UpGuard left 16,326 databases with readable tables. However, the finding was not a breach of Supabase itself. It involved insecure database configurations that could make data accessible through the Supabase Data API.<\/p>\n<p>Researchers identified Supabase database addresses and public API keys from web-accessible sources. They then tested whether common tables could be queried. Access depended on PostgreSQL grants and, where enabled and applicable, Row Level Security (RLS) policies.<\/p>\n<p>UpGuard has not publicly confirmed malicious third-party access to the exposed databases.<\/p>\n<h2>What Caused the Supabase Data Exposure?<\/h2>\n<p>UpGuard used BuiltWith technographic data and the Chrome UX Report dataset to identify around 300,000 domains with indicators of Supabase usage.<\/p>\n<p>Supabase key names and database addresses can appear in public JavaScript files. These details gave researchers the information needed to query the Data API. Whether data was accessible then depended on the project&#8217;s database configuration.<\/p>\n<p>UpGuard documented several significant cases:<\/p>\n<ul>\n<li><strong>US valet service CRM:<\/strong> Records for more than 100,000 customers were exposed. Every record contained a phone number, while about 78,000 also contained license plate numbers. Of the exposed email addresses, 4,560 belonged to third-party corporate domains, including universities and Fortune 500 companies.<\/li>\n<li><strong>Canadian immigration service:<\/strong> Nearly 5,000 user records were exposed, including 884 with a plaintext password.<\/li>\n<li><strong>Philippines OTP service:<\/strong> More than 2,000 users and over 100,000 SMS messages were exposed. The messages included OTP codes, sender IDs and SIM codes.<\/li>\n<\/ul>\n<p>UpGuard also documented significant exposure involving an African government consulate and an India-based adult creator platform.<\/p>\n<p>The researchers primarily inferred data types from table schemas. They manually investigated a smaller number of cases where metadata suggested significant exposure.<\/p>\n<h2>How Could a users Query Expose Supabase Data?<\/h2>\n<p>The exposure involved three separate layers: public client keys, database grants and RLS configuration.<\/p>\n<h3>Public Client Keys Are Not Secrets<\/h3>\n<p>Supabase&#8217;s legacy <code>anon<\/code> key is designed for use in public client code. Supabase now recommends publishable keys for public clients instead.<\/p>\n<p>With a publishable or legacy <code>anon<\/code> key, unauthenticated requests use the <code>anon<\/code> PostgreSQL role. Signed-in users use <code>authenticated<\/code>. PostgreSQL evaluates table grants before RLS.<\/p>\n<p>Supabase&#8217;s secret keys and legacy <code>service_role<\/code> keys provide elevated access through the <code>service_role<\/code> PostgreSQL role. Administrative requests operating as <code>service_role<\/code> without a user access token bypass RLS.<\/p>\n<p>Therefore, exposing a public client key is not by itself the security failure. The surrounding database permissions determine what that key can reach.<\/p>\n<h3>Legacy Grants Can Make Tables Reachable<\/h3>\n<p>Projects using Supabase&#8217;s legacy grant defaults can automatically make new tables reachable through the Data API.<\/p>\n<p>On those projects, tables created in <code>public<\/code> receive <code>SELECT<\/code>, <code>INSERT<\/code>, <code>UPDATE<\/code> and <code>DELETE<\/code> privileges for <code>anon<\/code>, <code>authenticated<\/code> and <code>service_role<\/code>.<\/p>\n<p>RLS then restricts rows for roles subject to RLS. If RLS is missing or improperly configured, a public client can potentially read rows permitted to the <code>anon<\/code> role.<\/p>\n<h3>RLS Depends on How Tables Are Created<\/h3>\n<p>Supabase&#8217;s Table Editor enables RLS by default. Tables created through the SQL Editor or other tooling require RLS to be enabled explicitly.<\/p>\n<p>UpGuard notes that programmatically created tables can therefore lack RLS unless the provisioning workflow enables it.<\/p>\n<p>One exposure path combines those conditions: automatic <code>anon<\/code> grants make a table reachable, while missing or inadequate RLS allows unintended row access.<\/p>\n<h3>How Scanning the users Table Scaled the Investigation<\/h3>\n<p>UpGuard queried for the common <code>users<\/code> table name and observed three possible outcomes:<\/p>\n<ul>\n<li>no accessible data;<\/li>\n<li>a hint identifying another accessible table; or<\/li>\n<li>a page of results.<\/li>\n<\/ul>\n<p>When <code>users<\/code> did not exist but other data was accessible, UpGuard reports that the response could provide another accessible table name as a hint.<\/p>\n<p>Separately, Supabase documents <code>42501<\/code> permission errors that can suggest the <code>GRANT<\/code> statement required for an attempted table operation.<\/p>\n<h2>What Has Supabase Changed to Reduce Data Exposure?<\/h2>\n<p>On May 29, 2025, developer Matt Palmer published details of <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2025-48757?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=supabase_data_exposure\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2025-48757<\/a>. The authorization issue affected certain Lovable-generated applications using Supabase without sufficiently restrictive RLS policies.<\/p>\n<p>Supabase enables RLS by default for tables created through the Table Editor. SQL- and tool-created tables still require explicit RLS configuration.<\/p>\n<p>Supabase has also started moving toward explicit Data API grants. The new setting began becoming the default for new projects on May 30, 2026. Supabase plans to apply it to all existing projects on October 30, 2026.<\/p>\n<p>Once enabled, newly created tables in <code>public<\/code> require an explicit grant before the Data API can access them. Existing tables retain their current grants.<\/p>\n<p>AI development provides additional context, but not a proven cause. Supabase reported in June 2026 that more than 60% of new databases were being launched by some form of AI tool.<\/p>\n<p>UpGuard argues that AI coding agents may help explain the exposure pattern. However, its methodology did not establish that every affected site was built using an AI coding agent.<\/p>\n<h2>What Is Confirmed About the Supabase Exposure?<\/h2>\n<table style=\"font-weight: 400;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"7\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"background-color: #e4e8eb; text-align: center;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Detail<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"background-color: #e4e8eb; text-align: center;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Status<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Databases with readable tables<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">16,326, confirmed by UpGuard&#8217;s scan<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Data types<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Primarily inferred from schemas; selected cases were manually investigated<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Payment-card data<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Schema indicators suggested possible payment-card data in a small number of cases; underlying records were not confirmed<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Malicious third-party access<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Not publicly confirmed<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">CVE<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">None for this finding; CVE-2025-48757 covers the earlier Lovable pattern<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Supabase vulnerability<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">None claimed; this finding concerns insecure configuration<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>How Should Teams Fix the Supabase Data Exposure?<\/h2>\n<p>Endpoint, OS or browser patches do not correct these database-access misconfigurations. Remediation belongs in Supabase database and Data API access controls.<\/p>\n<h3>1. Audit RLS and Exposed Objects<\/h3>\n<p>Review every table exposed through the Data API. Confirm that RLS is enabled where required and that policies restrict rows and operations as intended.<\/p>\n<p>Review views separately. On PostgreSQL 15+, <code>security_invoker = true<\/code> makes a view obey the underlying tables&#8217; RLS policies for the querying user. Otherwise, restrict client-role access or keep sensitive views in an unexposed schema.<\/p>\n<h3>2. Tighten Grants and Functions<\/h3>\n<p>Remove unnecessary privileges from Data API roles and grant access explicitly.<\/p>\n<p>Review <code>SELECT<\/code>, <code>INSERT<\/code>, <code>UPDATE<\/code> and <code>DELETE<\/code> permissions on tables. Also review <code>EXECUTE<\/code> on functions and <code>USAGE<\/code> or <code>SELECT<\/code> on sequences.<\/p>\n<p>Restrict function execution from <code>PUBLIC<\/code> and unnecessary roles.<\/p>\n<p>Pay particular attention to <code>SECURITY DEFINER<\/code> functions because they execute with the function owner&#8217;s privileges. Keep them out of schemas exposed through the Data API and explicitly configure <code>search_path<\/code>.<\/p>\n<h3>3. Reduce Data API Exposure<\/h3>\n<p>Disable the Data API when an application does not use Supabase client libraries or REST\/GraphQL data endpoints.<\/p>\n<p>Supabase states that its auto-generated REST endpoints do not respond when the Data API is disabled, regardless of grants or RLS configuration.<\/p>\n<p>Teams should also run Supabase&#8217;s Security Advisor and review its findings alongside the platform&#8217;s API security guidance.<\/p>\n<h3>4. Investigate Exposed Credentials<\/h3>\n<p>Determine whether readable tables contained passwords, tokens or other credentials.<\/p>\n<p>Rotate exposed tokens and reset passwords when investigation confirms or reasonably indicates credential exposure.<\/p>\n<p>For corporate accounts, MFA can reduce reliance on passwords alone. Phishing-resistant authentication provides stronger protection where appropriate.<\/p>\n<p>Database configuration changes address the root cause of this exposure. Endpoint and identity governance provide an additional defense-in-depth layer by helping organizations govern development tools and reduce the risk associated with exposed or reused credentials.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-for-data-security_-white-papers.webp?format=webp\" class=\"resource-box__image\" alt=\"Hexnode-for-data-security_-white-papers\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-for-data-security_-white-papers.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-for-data-security_-white-papers-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-for-data-security_-white-papers-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Hexnode-for-data-security_-white-papers-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Hexnode-for-data-security_-white-papers\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Strengthen Data Security Across Managed Endpoints\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore practical approaches to protecting business data and strengthening endpoint-level data security with Hexnode UEM.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/hexnode-for-data-security\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How Can Hexnode Support Teams Using Supabase?<\/h2>\n<p>The exposed component is a cloud database configuration. Hexnode does not replace Supabase RLS, PostgreSQL grants or Data API configuration. Its relevance sits at adjacent endpoint and identity layers.<\/p>\n<h3>Govern Developer Endpoints with Hexnode UEM<\/h3>\n<p>AI coding tools can generate database changes that still require security review. When these tools run on corporate endpoints, IT teams can govern the environment around them.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> provides application visibility and supported application controls on managed endpoints. Organizations can use these capabilities to identify known development tools and restrict unsanctioned applications where supported.<\/p>\n<p>Hexnode UEM also supports custom scripts on managed Windows, macOS and Linux devices, with RBAC over which technicians may run them and an auditable Action History.<\/p>\n<p>These controls do not fix Supabase configuration. They help govern the endpoints and development workflows surrounding it.<\/p>\n<h3>Protect Corporate Identities with Hexnode IdP<\/h3>\n<p>UpGuard found 4,560 valet-customer email addresses belonging to third-party corporate domains. Separately, the Canadian immigration service exposed 884 plaintext passwords.<\/p>\n<p>UpGuard did not establish that those passwords were reused corporate credentials. However, password reuse could turn third-party credential exposure into an enterprise account risk.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/idp\/\">Hexnode IdP<\/a> provides SSO and MFA, contextual authentication, and conditional access based on user identity, device compliance and security context. These controls can add verification or enforce access requirements according to the context of an access request.<\/p>\n<p>These controls provide an additional identity layer when credentials alone should not determine access.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/hexnode-idp-workforce-access-1024x535-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>How Can Hexnode IdP Secure Workforce Access to Enterprise Applications?<\/h4><p>Learn how Hexnode IdP combines MFA and device-aware access decisions for enterprise applications.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/hexnode-idp-workforce-application-access\/\" aria-label=\"How Can Hexnode IdP Secure Workforce Access to Enterprise Applications?\"><\/a><\/div><\/div><\/div>\n<h3>What Should Teams Take Away?<\/h3>\n<p>The Supabase data exposure documented by UpGuard did not require exploitation of a Supabase software vulnerability. Researchers identified 16,326 databases with readable tables using information available through web-accessible sources.<\/p>\n<p>Supabase&#8217;s move toward explicit grants reduces accidental Data API exposure for newly created <code>public<\/code> tables. However, existing tables retain their current grants.<\/p>\n<p>Teams should therefore review existing projects for appropriate grants, RLS policies and exposed database objects rather than assuming newer defaults have corrected previously deployed configurations.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Extend Security Controls to Your Managed Endpoints<\/h5><p>Manage applications, policies and endpoint workflows with Hexnode UEM. Start a fully functional 14-day trial.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign up now<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Supabase data exposure documented by UpGuard left 16,326 databases with readable tables. However, the&#8230;<\/p>\n","protected":false},"author":4,"featured_media":2114,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[19],"class_list":["post-2070","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-and-saas","product_category-unified-endpoint-management","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Supabase Data Exposure: 16,326 Databases Readable<\/title>\n<meta name=\"description\" content=\"Supabase data exposure left 16,326 databases with readable tables. Learn how grants, RLS and Data API settings contributed.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Supabase Data Exposure: 16,326 Databases Readable\" \/>\n<meta property=\"og:description\" content=\"Supabase data exposure left 16,326 databases with readable tables. Learn how grants, RLS and Data API settings contributed.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-29T06:38:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-01T05:02:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Supabase-Data-Exposure-How-16326-Databases-Became-Readable.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Supabase Data Exposure: How 16,326 Databases Became Readable\",\"datePublished\":\"2026-09-29T06:38:53+00:00\",\"dateModified\":\"2026-10-01T05:02:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/\"},\"wordCount\":1448,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Supabase-Data-Exposure-How-16326-Databases-Became-Readable.jpeg?format=webp\",\"articleSection\":[\"Cloud and SaaS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/\",\"name\":\"Supabase Data Exposure: 16,326 Databases Readable\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Supabase-Data-Exposure-How-16326-Databases-Became-Readable.jpeg?format=webp\",\"datePublished\":\"2026-09-29T06:38:53+00:00\",\"dateModified\":\"2026-10-01T05:02:36+00:00\",\"description\":\"Supabase data exposure left 16,326 databases with readable tables. Learn how grants, RLS and Data API settings contributed.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Supabase-Data-Exposure-How-16326-Databases-Became-Readable.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Supabase-Data-Exposure-How-16326-Databases-Became-Readable.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"Supabase Data Exposure How 16326 Databases Became Readable\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/supabase-data-exposure-16000-databases-rls\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Supabase Data Exposure: How 16,326 Databases Became Readable\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Supabase Data Exposure: 16,326 Databases Readable","description":"Supabase data exposure left 16,326 databases with readable tables. Learn how grants, RLS and Data API settings contributed.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/","og_locale":"en_US","og_type":"article","og_title":"Supabase Data Exposure: 16,326 Databases Readable","og_description":"Supabase data exposure left 16,326 databases with readable tables. Learn how grants, RLS and Data API settings contributed.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-29T06:38:53+00:00","article_modified_time":"2026-10-01T05:02:36+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Supabase-Data-Exposure-How-16326-Databases-Became-Readable.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Supabase Data Exposure: How 16,326 Databases Became Readable","datePublished":"2026-09-29T06:38:53+00:00","dateModified":"2026-10-01T05:02:36+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/"},"wordCount":1448,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Supabase-Data-Exposure-How-16326-Databases-Became-Readable.jpeg?format=webp","articleSection":["Cloud and SaaS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/","url":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/","name":"Supabase Data Exposure: 16,326 Databases Readable","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Supabase-Data-Exposure-How-16326-Databases-Became-Readable.jpeg?format=webp","datePublished":"2026-09-29T06:38:53+00:00","dateModified":"2026-10-01T05:02:36+00:00","description":"Supabase data exposure left 16,326 databases with readable tables. Learn how grants, RLS and Data API settings contributed.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Supabase-Data-Exposure-How-16326-Databases-Became-Readable.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Supabase-Data-Exposure-How-16326-Databases-Became-Readable.jpeg?format=webp","width":1340,"height":754,"caption":"Supabase Data Exposure How 16326 Databases Became Readable"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/supabase-data-exposure-16000-databases-rls\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Supabase Data Exposure: How 16,326 Databases Became Readable"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2070","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=2070"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2070\/revisions"}],"predecessor-version":[{"id":2113,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2070\/revisions\/2113"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/2114"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=2070"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=2070"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}