Vendor
Authorization Flaw in Capgo App Icon Update Path
1 TTP 1 CVEAn authorization vulnerability in the Capgo PUT /app/:id endpoint allows authenticated users to trick a privileged backend worker into overwriting restricted storage objects.
Authorization Bypass in capgo.app via Channel Permission Overrides
3 TTPs 1 CVEA vulnerability in capgo.app allows authenticated administrators to bypass organization boundaries by assigning channel-specific permissions to arbitrary external user UUIDs.
CVE-2026-88864 - Authorization Bypass in Capgo SSO Provisioning
1 TTP 1 CVEAn authorization vulnerability in the public.sso_providers table of Capgo allows attackers with an ordinary API key to bypass domain verification and enforce arbitrary SSO settings, leading to authentication disruption.
Information Disclosure in Capgo Supabase Integration via RPC Function
2 TTPs 1 CVEAn information disclosure vulnerability in Capgo (Cap-go/capgo) before version 12.128.2 allows unauthenticated attackers to enumerate organization existence. This flaw resides within the Supabase PostgREST SECURITY DEFINER RPC function 'public.rescind_invitation', which returns distinct error messages (NO_ORG vs. NO_RIGHTS) when called with only a publishable API key. This enables attackers to discover valid organization IDs, increasing the attack surface for targeted phishing or social engineering campaigns.
Capgo Email Change Vulnerability Bypasses Authentication (CVE-2026-56308)
2 TTPs 1 CVE 2 IOCsA vulnerability (CVE-2026-56308) in Capgo before version 12.128.2 allows an attacker with an authenticated session to change a user's email address without re-authentication or verification of the existing email, leading to account takeover through recovery mechanisms and multi-factor authentication bypass.
Capgo Privilege Escalation via Retained Super_Admin Privileges (CVE-2026-56241)
1 TTP 1 CVEA privilege escalation vulnerability, CVE-2026-56241, in Capgo versions prior to 12.128.2 allows demoted super_admin users to retain access to critical RPCs, enabling them to indefinitely enumerate and bulk delete non-compliant bundles across an organization.
CVE-2026-56238 - Capgo Supabase PostgREST Information Disclosure
1 rule 2 TTPs 1 CVEAn information disclosure vulnerability (CVE-2026-56238) in Capgo before 12.128.2's Supabase PostgREST global_stats endpoint allows unauthenticated attackers to retrieve sensitive financial and operational metrics using a public API key.
Capgo API Key Information Disclosure Vulnerability (CVE-2026-56303)
1 rule 1 TTP 1 CVEAn information disclosure vulnerability (CVE-2026-56303) in Capgo versions before 12.128.2 allows unauthenticated attackers to retrieve sensitive API key metadata, including user ID, mode, organization scoping, and expiration details, by exploiting a misconfigured PostgreSQL function via the `/rest/v1/rpc/find_apikey_by_value` endpoint.
Capgo Information Disclosure in get_orgs_v7 RPC Function (CVE-2026-56279)
1 rule 4 TTPs 1 CVECapgo versions prior to 12.128.2 are vulnerable to an information disclosure flaw in the `get_orgs_v7(userid)` RPC function, allowing unauthenticated attackers to retrieve sensitive foreign user and organization data by supplying arbitrary user UUIDs.
Capacitor Updater Vulnerability Allows Malicious Update Installation via Private Key Distribution
2 TTPs 1 CVEA vulnerability, CVE-2026-56254, in @capgo/capacitor-updater (Cap-go/capgo) before version 12.128.2 allows an attacker to create and distribute validly signed malicious application updates by leveraging the improper distribution of a private key to each client device, enabling man-in-the-middle or server compromise scenarios.
CVE-2026-56250: Capgo R2 Bundle Object Deletion via Mutable r2_path
2 TTPs 1 CVE 2 IOCsA critical vulnerability, CVE-2026-56250, in Capgo before version 12.128.2 allows an authenticated attacker with upload-scoped API keys to manipulate the app_versions.r2_path field via PostgREST, leading to arbitrary R2 bundle object deletion and denial of service.
CVE-2026-56246 - Capgo Broken Access Control in Organization Management API
3 TTPs 1 CVECapgo versions prior to 12.128.2 contain a broken access control vulnerability (CVE-2026-56246) in their organization management API where a scoped API key inherits the full permissions of its owner-user, allowing an attacker to perform destructive operations against unauthorized organizations, bypassing intended scope and leading to privilege escalation and impact.