PT-2026-54021 · Cap Go · Cap-Go

·

CVE-2026-56219

·

Published

2026-06-30

·

Updated

2026-07-01

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description An authentication bypass exists due to an improper NULL comparison in the authorization gate. Unauthenticated attackers can exploit this by using a public API key to access the PostgREST RPC endpoint and call the public.get org user access rbac() function. This allows the disclosure of organization membership, RBAC (Role-Based Access Control) role bindings, and member email addresses.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56219
GHSA-VVM7-XHCJ-M94H

Affected Products

Cap-Go