Junglewise Threat Intelligence

CVE-2026-56249: Capgo authorization bypass in channel creation endpoint

CVE-2026-56249 · Severity: high · CVSS 7.6 · Published 2026-06-30

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates, contains a security flaw in how it handles the creation of communication channels. An authorized user can intentionally reuse the name of an existing channel (such as 'production') to take over ownership and modify its settings. This could allow an attacker to disrupt app deployments, push unauthorized updates, or lock legitimate administrators out of critical configurations.

Technical details

An authorization bypass exists in Capgo's channel creation flow due to a logic mismatch between validation and execution in the `updateOrCreateChannel()` function. While the initial existence check is correctly scoped to the caller's identity, the subsequent database `upsert` operation uses a conflict target of `(app_id, name)` that ignores the original creator. An authenticated attacker with `app.create_channel` permissions can submit a POST request to `/channel` using the name of an existing channel owned by another user. This triggers an overwrite of the existing record, reassigning the `created_by` field to the attacker and allowing them to modify critical configurations. The issue is fixed in version 12.128.2.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-03-03: advisory: GitHub Security Advisory published
  • 2026-06-30: disclosed: NVD publication date
  • 2026-06-30: patched: Fix released in version 12.128.2

References

Related threats