PT-2026-89375 · Cap Go · Capgo.App

·

CVE-2026-88864

·

Publicado

2026-09-10

·

Atualizado

2026-09-10

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
Capgo (capgo.app) fails to restrict direct write access to the public.sso providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce sso=true, bypassing the intended backend SSO provisioning route (supabase/functions/ backend/private/sso/providers.ts) and its controls: the Enterprise plan requirement, SSO provider creation via the Supabase Management API, DNS TXT domain-ownership verification, the pending verification → verified → active status transition, and issuance of a trusted provider ID by Supabase Auth. The forged row is trusted by SSO discovery and enforcement logic, including the unauthenticated login preflight endpoint /private/sso/check-domain, which then reports {"has sso": true, "enforce sso": true} for domains that were never verified, allowing attacker-controlled SSO enforcement to be asserted for arbitrary domains and disrupting normal login. All versions are affected; at the time of the advisory no patch was available.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-88864

Produtos afetados

Capgo.App