PT-2026-99294 · Cap Go · Capgo.App

·

CVE-2026-100623

·

Publicado

2026-09-26

·

Atualizado

2026-09-28

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
🚨 CVE-2026-100623 Capgo (capgo.app) exposes the legacy membership table public.org users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin rights in the target organization (public.check min rights('admin', ...)); they do not require a pending invitation in tmp users, acceptance of an invite token via /private/accept invitation, any action by the target user, or the membership/role-consistency and anti-escalation checks enforced by the RBAC role-binding path. As a result, an authenticated user who is an admin of an organization can INSERT or UPDATE org users rows directly to add any existing public.users account as an active member of that organization with user right="admin", bypassing the invitation and role-assignment workflow entirely. In testing, an account with no prior access to the organization or its apps could, after such a direct insert, read the organization and app and pass check min rights. All versions are affected and no patch was available at the time of publication.
🎖@cveNotify

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-100623

Produtos afetados

Capgo.App