{"id":"CVE-2026-62247","published":"2026-09-21T20:17:27.470","lastModified":"2026-09-21T20:17:27.470","description":"Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy when a private-channel client is allowed presence.write but explicitly denied presence.read. Under that differential policy, the client can receive presence_diff messages containing other members' presence metadata, including application-defined location, online-status, roster, viewing, or typing information. Deployments with uniform presence visibility have no differential, and postgres_changes row data is unaffected. This issue is fixed in version 2.111.2.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://github.com/supabase/realtime/commit/c039bca9b57c2e554a67fdf462970b54641d82eb","tags":[]},{"url":"https://github.com/supabase/realtime/pull/1969","tags":[]},{"url":"https://github.com/supabase/realtime/releases/tag/v2.111.2","tags":[]},{"url":"https://github.com/supabase/realtime/security/advisories/GHSA-rcr8-2525-4r7p","tags":[]}],"exploitRefs":[{"url":"https://github.com/supabase/realtime/commit/c039bca9b57c2e554a67fdf462970b54641d82eb","tags":[]},{"url":"https://github.com/supabase/realtime/pull/1969","tags":[]},{"url":"https://github.com/supabase/realtime/releases/tag/v2.111.2","tags":[]},{"url":"https://github.com/supabase/realtime/security/advisories/GHSA-rcr8-2525-4r7p","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows a client with presence.write permission but denied presence.read to receive presence metadata from other clients, potentially exposing sensitive information like location and online status.","exploitability":"Exploitation requires specific authorization levels; difficult without precise permissions setup.","blast_radius":"If exploited, could lead to data leakage in deployments with mixed visibility policies.","remediation":"Update Supabase Realtime to version 2.111.2 or higher to apply the necessary security fix.","tags":["auth-bypass","info-leak","websocket"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:20:10.922Z"}}