Over 16,000 Supabase databases expose PII, passwords, auth tokens
BleepingComputer published a report stating that over 16,000 Supabase databases expose data, with the headline listing personally identifiable information, passwords, and authentication tokens among the exposed data types. The article's URL slug attributes the exposure to misconfigured Supabase apps, describing the situation as data exposed in more than 16,000 databases. The source material available for this item is limited to the article title, its URL, and a truncated fragment of the page markup; the full body text was not included. As a result, the excerpt does not specify which organizations or projects are affected, what configuration error produced the exposure, how the databases were identified, whether any party was notified, or whether the exposure has been addressed. Those details cannot be stated here without going beyond what the source provides. What the source does support is the scale — over 16,000 databases — the platform involved, Supabase, and the categories of data named in the headline: PII, passwords, and auth tokens. No CVE identifier, version number, or vendor response is present in the supplied text.
The report indicates that misconfigured Supabase apps can leave PII, passwords, and authentication tokens exposed across thousands of databases.