Junglewise Threat Intelligence

CVE-2026-56253: Capgo improper access control in get_org_members RPC

CVE-2026-56253 · Severity: high · CVSS 7.5 · Published 2026-06-21

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates, contained a security flaw that allowed unauthorized individuals to view private organization details. By using a publicly available key and an organization's unique ID, an attacker could download a full list of members, including their email addresses, account roles, and pending invitations. This exposure of personally identifiable information (PII) could be used for targeted phishing attacks or to map out a company's internal structure.

Technical details

An improper access control vulnerability exists in the Supabase RPC function 'public.get_org_members' within Capgo. The function was exposed to the 'anon' role and failed to validate the 'auth.uid()' of the requester, relying instead on a user-supplied 'guild_id' (organization UUID) while ignoring the 'user_id' parameter. A remote, unauthenticated attacker can exploit this by sending a crafted POST request to the RPC endpoint using a public 'sb_publishable_*' key. Successful exploitation results in the disclosure of sensitive member data, including email addresses, user UUIDs, roles, and pending invitations. The issue was addressed in version 12.128.2.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-03-03: advisory: Vendor advisory published on GitHub
  • 2026-06-21: disclosed: CVE published and NVD record created

References

Related threats