Junglewise Threat Intelligence

CVE-2026-56235: Cap-go capgo authorization bypass in Supabase RPC functions

CVE-2026-56235 · Severity: medium · CVSS 5.3 · Published 2026-06-20

Technologies: Cap-go. Vendors: Cap-go.

Executive brief

Cap-go, a platform for managing app updates, contained a security flaw where sensitive usage data was accessible to unauthorized users. An attacker could use a public API key to view private business metrics such as monthly active users, bandwidth usage, and installation counts for any organization on the platform. This could lead to the exposure of competitive business intelligence and the identification of valid customer accounts.

Technical details

An authorization bypass exists in Cap-go's Supabase PostgREST RPC functions, specifically get_app_metrics, get_global_metrics, and get_total_metrics. These functions were granted to the 'anon' role without implementing internal checks for organization membership or specific permissions. By providing a public Supabase publishable API key and a target organization ID, an unauthenticated attacker can retrieve telemetry data including MAU, bandwidth, and app IDs. The vulnerability also acts as an account oracle, as valid organization IDs return data while invalid ones return an empty array. The issue is resolved in version 12.128.2.

Affected products

  • Cap-go capgo < 12.128.2

Timeline

  • 2026-03-17: advisory: Vendor advisory published on GitHub
  • 2026-06-20: disclosed: CVE published to NVD

References