Junglewise Threat Intelligence

CVE-2026-56251: Capgo privilege escalation via broken RLS in org_users

CVE-2026-56251 · Severity: medium · CVSS 6.5 · Published 2026-06-21

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and deployments, contained a security flaw in its user management system. This vulnerability allowed an existing administrator to bypass security restrictions and grant themselves 'super admin' status. If exploited, an attacker with administrative access could gain full control over the entire organization's account, potentially leading to unauthorized system changes or service disruptions.

Technical details

A privilege escalation vulnerability exists in Capgo versions prior to 12.128.2 due to an incorrectly configured Row Level Security (RLS) policy in the 'org_users' database table. The flaw allows an authenticated user with 'admin' privileges to modify their own or others' roles to 'super_admin' because the RLS policy does not sufficiently restrict updates to sensitive columns. This is a network-reachable vulnerability that requires high privileges (admin) to execute. Successful exploitation results in a complete compromise of integrity and availability within the affected organization. The issue has been addressed in version 12.128.2.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-02-10: advisory: Initial GitHub security advisory published
  • 2026-06-21: disclosed: NVD and VulnCheck publication date

References

Related threats