PT-2026-99294 · Cap Go · Capgo.App

·

CVE-2026-100623

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
🚨 CVE-2026-100623 Capgo (capgo.app) exposes the legacy membership table public.org users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin rights in the target organization (public.check min rights('admin', ...)); they do not require a pending invitation in tmp users, acceptance of an invite token via /private/accept invitation, any action by the target user, or the membership/role-consistency and anti-escalation checks enforced by the RBAC role-binding path. As a result, an authenticated user who is an admin of an organization can INSERT or UPDATE org users rows directly to add any existing public.users account as an active member of that organization with user right="admin", bypassing the invitation and role-assignment workflow entirely. In testing, an account with no prior access to the organization or its apps could, after such a direct insert, read the organization and app and pass check min rights. All versions are affected and no patch was available at the time of publication.
🎖@cveNotify

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100623

Affected Products

Capgo.App