CVE-2026-62247
6.5 MEDIUMpublic exploit availablePublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw allows a client with presence.write permission but denied presence.read to receive presence metadata from other clients, potentially exposing sensitive information like location and online status.
- Exploitability
- Exploitation requires specific authorization levels; difficult without precise permissions setup.
- Blast radius
- If exploited, could lead to data leakage in deployments with mixed visibility policies.
- Prioritized remediation
- Update Supabase Realtime to version 2.111.2 or higher to apply the necessary security fix.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy when a private-channel client is allowed presence.write but explicitly denied presence.read. Under that differential policy, the client can receive presence_diff messages containing other members' presence metadata, including application-defined location, online-status, roster, viewing, or typing information. Deployments with uniform presence visibility have no differential, and postgres_changes row data is unaffected. This issue is fixed in version 2.111.2.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-863
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-52743PoC
- LOWCVE-2026-55060PoC
- MEDIUMCVE-2025-71420PoC
- HIGHCVE-2026-25703PoC
- MEDIUMCVE-2026-63248PoC
- HIGHCVE-2026-6639
- MEDIUMCVE-2026-70491PoC
- MEDIUMCVE-2026-75158PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.