{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/sso-bypass/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:capgo:capgo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-88864"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["capgo.app (all versions)"],"_cs_severities":["high"],"_cs_tags":["sso-bypass","cloud-security","api-security"],"_cs_type":"advisory","_cs_vendors":["Capgo"],"content_html":"\u003cp\u003eCapgo (capgo.app) contains a critical authorization flaw (CVE-2026-88864) stemming from improperly restricted access to the public.sso_providers table exposed via Supabase PostgREST. The vulnerability enables any user with a standard Capgo API key to perform direct write operations to this database table. By inserting a row with status set to 'active' and enforce_sso set to 'true', an attacker effectively bypasses the backend provisioning route defined in supabase/functions/_backend/private/sso/providers.ts.\u003c/p\u003e\n\u003cp\u003eThis bypass invalidates critical security controls, including the Enterprise plan entitlement checks, domain-ownership verification through DNS TXT records, and the mandatory transition from pending_verification to verified status. Consequently, the application trusts these forged entries during SSO discovery and enforcement logic, including the unauthenticated /private/sso/check-domain preflight endpoint. This allows an attacker to assert SSO enforcement for arbitrary domains, effectively hijacking the login flow for legitimate users. As of the advisory date, no patch is available for this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized assertion of SSO enforcement for arbitrary domains. This disrupts authentication services, potentially leading to denial-of-service for legitimate users who are forced into invalid SSO workflows. The vulnerability bypasses the Enterprise plan tiering, allowing unauthorized access to enterprise-grade features. No specific victim counts were reported, but the flaw affects all deployments of the capgo.app platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring for anomalous database write activity or API key usage until a vendor patch is issued.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict access to the Supabase PostgREST interface to known-good administrative IP ranges.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized INSERT or UPDATE operations on the public.sso_providers table.\u003c/li\u003e\n\u003cli\u003eReview all existing entries in the public.sso_providers table for unexpected configurations that deviate from legitimate enterprise tenant provisioning.\u003c/li\u003e\n\u003cli\u003eImplement strict row-level security (RLS) policies within Supabase to prevent API-key-based writes to the sso_providers table.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T15:07:07Z","date_published":"2026-09-10T15:07:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-capgo-sso-bypass/","summary":"An authorization vulnerability in the public.sso_providers table of Capgo allows attackers with an ordinary API key to bypass domain verification and enforce arbitrary SSO settings, leading to authentication disruption.","title":"CVE-2026-88864 - Authorization Bypass in Capgo SSO Provisioning","url":"https://feed.craftedsignal.io/briefs/2026-09-capgo-sso-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Sso-Bypass","version":"https://jsonfeed.org/version/1.1"}