Cap Go · Cap-Go · CVE-2026-100612
**Name of the Vulnerable Software and Affected Versions**
Capgo (capgo.app) versions prior to 12.261.0
**Description**
An incomplete access-control fix in the `public.sso providers` table allows a user with `org admin` permissions and the `org.update settings` permission to perform vertical privilege escalation. While the `enforce sso provider client update guard()` function restricts updates to certain columns, the `provider id`, `metadata url`, and `attribute mapping` variables remain writable. Due to permissive table grants and row-level security policies that do not restrict specific columns, an attacker can use a PATCH request via PostgREST to change the `provider id` to an identity provider (IdP) they control. By asserting the organization owner's email through their own IdP, the attacker can merge their identity with the owner's account, resulting in account takeover, password nullification, and lockout of the legitimate owner. This requires the organization to have an active SSO provider configured and the attacker to already possess `org admin` status.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.