PT-2026-51503 · Cap Go · Cap-Go

·

CVE-2026-56243

·

Published

2026-06-23

·

Updated

2026-06-23

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description A security control bypass exists in the PostgREST/RLS plane where plaintext API keys are accepted through the capgkey header, even when enforce hashed api keys is enabled. This allows attackers to bypass organization-level hashed-key enforcement by sending plaintext API keys directly to the PostgREST/RLS plane to access protected resources.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56243
GHSA-6G74-8CPQ-G2C8

Affected Products

Cap-Go