Junglewise Threat Intelligence

CVE-2026-56238: Capgo information disclosure in Supabase PostgREST global_stats endpoint

CVE-2026-56238 · Severity: high · CVSS 7.5 · Published 2026-07-12

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates, suffered from a security flaw that exposed sensitive business data to the public. An unauthenticated person could access internal financial metrics, including monthly recurring revenue, total revenue, and customer counts across different plan tiers. This information could be used by competitors for business intelligence or by attackers to understand the scale and usage patterns of the platform.

Technical details

An information disclosure vulnerability exists in Capgo versions prior to 12.128.2 due to improper access control on the Supabase PostgREST 'global_stats' endpoint. The 'public.global_stats' table was exposed to the 'anon' role, allowing any remote attacker with the public API key (which is typically embedded in client-side code) to query sensitive data. Exposed metrics include Monthly Recurring Revenue (MRR), total revenue, revenue breakdowns by plan tier, customer counts, and operational telemetry such as device and plugin statistics. The issue was resolved by restricting access to the endpoint and ensuring Row Level Security (RLS) prevents public reads.

Affected products

  • Capgo Capgo before 12.128.2

Timeline

  • 2026-03-17: advisory: GitHub Security Advisory published
  • 2026-07-12: disclosed: NVD publication date

References

Related threats