Supabase clients expose user data openly on the web
Multiple clients of the database platform Supabase have incorrectly configured their applications, resulting in the exposure of large volumes of user data on the public internet.

What happened?
Multiple clients using the database platform Supabase have publicly exposed large amounts of user data. According to reports from 25 September 2026, the leaks are due to applications—including those developed using AI—not being correctly configured or secured.
Key facts
| Rapporterat datum | 25 september 2026 |
|---|---|
| Berörd plattform | Supabase |
| Orsak | Felkonfigurerade appar och säkerhetsbrister |
”The findings highlight how AI-generated and vibe-coded apps can spill and expose users' data when not configured or secured properly.”
Why it matters
The incident highlights the security risks inherent in building and deploying applications without adequate security controls. When settings for permissions and database access are overlooked, sensitive data becomes accessible to anyone on the internet.
Who is affected?
The event affects developers, businesses, and users who rely on Supabase as their database and backend service. Individuals whose personal data was contained within the misconfigured applications are directly impacted by the exposure.
Impact on the EU
Security flaws and misconfigurations leading to data leaks directly implicate Swedish and European organisations under the EU General Data Protection Regulation (GDPR), where inadequate access control can result in significant administrative fines.
What else you should know
The source clarifies that the issue does not lie with the Supabase database platform itself, but rather with how clients configure their security policies and permissions when building and distributing their applications.
Quick answers about this story
Vad har hänt?
När hände det?
Varför spelar det roll?
Vilka berörs av läckan?
The link opens in a new window and leads to the publisher's own site.
Källan har spårats automatiskt från utgivaren via Aheadlines signalkedja.
Get similar news straight to your inbox
The reader's room
Send in a question or an addition. The newsroom reads everything before it's published and replies when relevant. No AI-generated text – just people.
Sign in to submit a comment or question.
Read the article through your role
- Decide whether this affects strategy over 6–12 months or is just noise.
- Discuss with leadership: do we own the right question or does ownership need to move?
- Ask: what risk are we taking by NOT acting on this this quarter?
Generated angle — not editorial analysis of "Supabase clients expose user data openly on the web"