PT-2026-51222 · Cap Go · Cap-Go

·

CVE-2026-56251

·

Published

2026-06-21

·

Updated

2026-06-22

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description A broken row level security (RLS) policy in the org users table allows authenticated users to elevate their privileges from admin to super admin. This insufficient RLS enforcement enables attackers to gain unauthorized super admin access and compromise system security.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

LPE

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56251
GHSA-9XQH-F26V-9C9H

Affected Products

Cap-Go