Missing Row-Level Security Quietly Became One of the Biggest Database Breach Causes
Failing to enable Row-Level Security (RLS) on database tables has emerged as a leading cause of data breaches in 2025-2026, with encryption receiving far more attention than this more critical access-control gap. A May 2025 vulnerability (CVE-2025-48757) exposed data from 303 endpoints across 170 apps built with the AI tool Lovable, because Supabase RLS was never switched on. Security researchers have also identified hundreds to thousands of Supabase instances globally that can be queried using only a public anonymous key and a basic curl request. The problem is not new or platform-specific — a similar Firebase misconfiguration previously leaked sensitive data belonging to over 1.8 million users across more than 900 apps in health, finance, and education. Supabase has since enabled RLS by default on new tables, but experts warn the risk remains highest during database migrations, when access-control logic must be manually rebuilt from scratch under time pressure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in