Junglewise Threat Intelligence

CVE-2026-62247: Supabase Realtime authorization bypass in presence.read row-level security

CVE-2026-62247 · Severity: medium · CVSS 6.5 · Published 2026-09-21

Executive brief

Supabase Realtime is a real-time database synchronization service that uses WebSockets to push presence and data changes to application clients. Prior to version 2.111.2, a flaw in authorization logic allowed clients with write-only permissions to read other users' presence metadata (such as location, online status, or typing indicators) that they were explicitly denied access to. This could expose sensitive user activity information in applications that rely on row-level security policies to control who can see whose presence.

Technical details

The vulnerability exists in the Realtime authorization module where presence.read row-level security policies were not correctly enforced when a client had presence.write but explicit presence.read denial. Clients in private channels could receive presence_diff messages containing other members' presence metadata despite failing the read permission check. The fix, deployed in 2.111.2, ensures the presence.read permission is properly evaluated and enforced before sending presence updates.

Affected products

  • Supabase Realtime before 2.111.2

Timeline

  • 2026-09-21: disclosed: CVE-2026-62247 published
  • 2026-06-23: patched: Fix merged in version 2.111.2

References