Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: secrets-hygiene (2 articles)Clear

Over 16,000 misconfigured Supabase databases expose personal data passwords and auth tokens

UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens, with a very small subset appearing to include credit card data. Supabase is an open-source PostgreSQL development platform, popular with developers using AI tools, which now account for more than 60 percent of newly created databases. UpGuard analyzed about 300,000 domains showing Supabase use and inferred exposed data types from table schemas. More than half of the exposed databases held PII, with a smaller subset exposing passwords and tokens. One US valet service alone exposed over 100,000 customer records, showing how missing access controls turn convenient backends into open data stores.

Check
Audit Supabase projects for tables readable without authentication, enable row-level security and proper policies, and rotate any exposed tokens or passwords.
Affected
Supabase projects deployed without row-level security or access policies expose their tables, leaking PII, credentials, and auth tokens to anyone who queries them.
Fix
Turn on row-level security, restrict anonymous access, review AI-generated backends for missing controls, and monitor for unauthorized table reads.

SolarWinds Access Rights Manager hard coded key enables unauthenticated remote code execution

SolarWinds patched a high-severity flaw in Access Rights Manager, tracked as CVE-2026-28326 and rated 8.8, that stems from a hard-coded static key and can lead to unauthenticated remote code execution. The issue affects all Access Rights Manager 2026.2 and prior releases and is fixed in 2026.2.1. SolarWinds credited Armadin researcher Kai Huang and reported no evidence of exploitation in the wild. The advisory arrives alongside separate fixes: a Web Help Desk SAML authentication bypass, a Web Help Desk denial-of-service issue, and sixteen Serv-U flaws that could allow privilege escalation, code execution, and creation of administrator accounts.

Check
Inventory SolarWinds Access Rights Manager instances, confirm versions at or below 2026.2, and upgrade to 2026.2.1 on an emergency schedule.
Affected
Access Rights Manager 2026.2 and earlier ship a hard-coded static key that an unauthenticated attacker can use to reach remote code execution.
Fix
Patch to 2026.2.1, restrict management interfaces to trusted networks, and separately update Web Help Desk and Serv-U to their fixed builds.