PT-2026-51408 · Cap Go · Cap-Go

·

CVE-2026-56311

·

Published

2026-06-22

·

Updated

2026-06-23

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description An authorization bypass exists in the public.get current plan max org() RPC function. Unauthenticated attackers can use the public Supabase key to call this endpoint with any organization UUID to retrieve arbitrary organization plan limits. This allows the disclosure of billing information, including Monthly Active Users (MAU), bandwidth, storage, and build time limits.
Recommendations Update to version 12.128.2 or later. As a temporary mitigation, restrict access to the public.get current plan max org() function.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56311
GHSA-V3JP-R95G-X4MM

Affected Products

Cap-Go