DBX
DBX home
Acme ProductionPRODUCTIONExit Demo
Run Scan
Findings
High

Anonymous role granted access to public.webhook_endpoints

Affected:
public.webhook_endpoints
Category:
Permissions
Confidence:
high
First detected:
2026-08-12 11:04Z
Last verified:
2026-08-16 09:41Z

Summary

anon has SELECT, and RLS policies allow access without identity verification.

Why this matters

Anyone with the publishable API key could potentially access this relation without signing in, depending on RLS.

Evidence

Role
anon
Privileges
SELECT
RLS Enabled
true
Applicable Policy
Public endpoint directory (USING: true)

Facts above were derived by the scanner from database metadata. No model output is involved in the verdict.

Technical details

RLS is enabled, but a policy applying to anon/PUBLIC has a permissive or easily bypassed USING clause.

Attack path

INTERNETINTERNET✓anonymousROLE⚠authenticatedROLE!Data APIPOSTGREST✓RPC/REST/V1/RPC⚠get_invoice()SECURITY DEFINER⚠refresh_usage_total…SECURITY DEFINER!v_customer_billingDEFINER VIEW!profilesRLS ENABLED!support_ticketsRLS ENABLED!webhook_endpointsRLS ENABLED⚠pricing_plansRLS ENABLED⚠subscriptionRLS DISABLED⚠_http_responseRLS DISABLED⚠avatarsPUBLIC BUCKET!

internet → anon → rest → public.webhook_endpoints

recommended remediation

Unlock Full Audit (Demo)

Bottom 35% of Supabase projects we've scanned.
Production-Ready Fixes
Ready to scan your own database?
Buy Remediation Credits — $19

Includes 5 Activation Credits

Review anonymous privileges on public.webhook_endpoints.

Current

Role: anon GRANTED PRIVILEGES SELECT granted RLS EFFECTIVE ACCESS RLS ENABLED: true Applicable policies: Public endpoint directory — USING (true)

Recommended Review

Anonymous access is currently permitted. If public access is intentional: • Keep required public policies. • Verify that each policy exposes only intended rows and operations. If public access is not intentional: • Restrict or remove applicable public policies. • Revoke unnecessary anon privileges. Application intent is required before generating a migration.

Expected security effect

  • Modifying this could break legitimate public access or Supabase features.

No migration generated — application intent required.

Compatibility risk

high

Any public surface reading this relation without a session will break.

DBX never applies SQL to your database.