Junglewise Threat Intelligence

CVE-2026-56247: Capgo privilege escalation via cross-scope RBAC role assignment

CVE-2026-56247 · Severity: high · CVSS 8.8 · Published 2026-06-30

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and deployments, contained a flaw in its permission management system. An organization administrator could assign high-level permissions to a user before they even joined the organization, and these permissions would incorrectly persist after the user accepted their invitation. This could allow a low-privileged user to gain full administrative control over specific applications, potentially leading to unauthorized data access or service disruption.

Technical details

A privilege escalation vulnerability exists in Capgo's RBAC system due to insufficient validation in the role assignment endpoint (`role_bindings.ts`). The system fails to verify that a role's `scope_type` (e.g., organization-wide) matches the requested binding scope (e.g., app-specific). Furthermore, the system allows these roles to be assigned to pending invitees. Because the authorization resolver (`rbac_has_permission`) trusts the `role_id` without verifying scope compatibility, and the invitation acceptance process fails to clear these malformed bindings, a low-privilege user can inherit high-level permissions (such as `org_super_admin`) restricted to a specific application. This allows the attacker to perform unauthorized actions via direct Row-Level Security (RLS) updates. The issue is patched in version 12.128.2.

Affected products

  • Capgo Capgo before 12.128.2

Timeline

  • 2026-05-07: advisory: GitHub Security Advisory published
  • 2026-06-30: disclosed: NVD publication date

References

Related threats