Authorization Flaw in Supabase Realtime Leading to Unintended Access
CVE-2026-62247

6.5MEDIUM

Key Information:

Vendor

Supabase

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-62247?

Supabase Realtime, which facilitates real-time data interaction through WebSockets, contains a vulnerability where the authorization checks for presence.read do not properly enforce row-level security. This allows clients with only presence.write permissions to receive presence_diff messages that should otherwise be restricted, potentially exposing sensitive information like user locations, online statuses, and typing indicators. This issue has been resolved in version 2.111.2.

Affected Version(s)

realtime < 2.111.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.