Junglewise Threat Intelligence

CVE-2026-56244: Capgo information disclosure in webhooks table via Supabase REST

CVE-2026-56244 · Severity: high · CVSS 7.1 · Published 2026-06-24

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and webhooks, contained a security flaw where users with limited 'read-only' access could view sensitive webhook signing secrets. By obtaining these secrets, an unauthorized user could impersonate the Capgo service and send fake, yet seemingly authentic, data to other business systems. This could lead to unauthorized actions in downstream automated workflows, such as financial transactions or operational changes, by tricking those systems into believing the requests came from a trusted source.

Technical details

A vulnerability in Capgo versions prior to 12.128.2 stems from insufficient Row-Level Security (RLS) policies on the 'public.webhooks' table within its Supabase backend. Specifically, the 'secret' column was not excluded from SELECT operations available to non-admin/read-only API keys. An authenticated attacker with a low-privileged API key can query the Supabase REST endpoint (/rest/v1/webhooks) to retrieve the 'whsec_*' signing secrets. With these secrets, the attacker can compute valid HMAC-SHA256 signatures and forge 'X-Capgo-Signature' headers, allowing them to send spoofed webhook events to configured receivers that bypass authenticity and integrity checks. The issue is resolved in version 12.128.2 by restricting access to the secret column.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-03-17: advisory: GitHub Security Advisory published
  • 2026-06-24: disclosed: CVE published to NVD

References

Related threats