Junglewise Threat Intelligence

CVE-2026-100612: Capgo access control bypass in SSO provider configuration

CVE-2026-100612 · Severity: high · CVSS 7.2 · Published 2026-09-26

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a mobile application platform, has a flaw in its single sign-on (SSO) configuration that allows organization administrators to redirect authentication to an attacker-controlled identity provider. By manipulating which identity provider a domain trusts, an attacker with admin privileges can impersonate the organization owner, take over their account, and lock them out. The vulnerability requires the attacker to already hold admin access within the target organization and for SSO to be configured.

Technical details

The vulnerability stems from incomplete row-level security enforcement in PostgreSQL: the public.sso_providers table has a BEFORE UPDATE guard that freezes certain columns (dns_verified_at, domain, status, enforce_sso) but leaves provider_id, metadata_url, and attribute_mapping writable. Since PostgreSQL RLS policies constrain only which rows may be updated rather than which columns within those rows, an org_admin can PATCH the provider_id column via PostgREST to point to an attacker-controlled IdP. This breaks the trust anchor binding email domains to authorized providers, allowing authentication bypass and account takeover via identity merge.

Affected products

  • Capgo Capgo through 12.261.0

Timeline

  • 2026-09-26: disclosed

Related threats