Vendor
Capgo vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 91 vulnerabilities in Capgo: 0 in the last 7 days and 42 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88864, was published on 10 September 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 42
- Critical, all time
- 2
- Exploited in the wild
- 0
About Capgo
A provider of cloud-based update and deployment services for Capacitor and Ionic applications.
Capgo technologies
- Capgo83
Latest Capgo vulnerabilities
- CVE-2026-88864: Capgo authentication bypass via PostgREST direct write to SSO providerscriticalCVSS 9.1EPSS 0.4%
- CVE-2026-88860: Capgo authorization bypass via stale channel permission overridesmediumCVSS 6.3EPSS 0.3%
- CVE-2026-56336: Capgo information disclosure in SSO check-domain endpointmediumCVSS 5.3
- CVE-2026-56313: Capgo improper authorization in SSO prelink endpointhighCVSS 8.1
- CVE-2026-56308: Capgo insufficient authentication in email change endpointhighCVSS 7.3
- CVE-2026-56281: Capgo SQL injection in admin_stats endpointlowCVSS 3.8
- CVE-2026-56252: Capgo incorrect authorization in webhook test endpointmediumCVSS 5.4
- CVE-2026-56241: Capgo privilege escalation via stale RBAC demotion recordshighCVSS 8.3
- CVE-2026-56238: Capgo information disclosure in Supabase PostgREST global_stats endpointhighCVSS 7.5
- CVE-2026-56303: Capgo information disclosure in find_apikey_by_value RPC functionhighCVSS 7.5
- CVE-2026-56240: Capgo billing authorization bypass in plan_valid calculationmediumCVSS 4.3
- CVE-2026-56335: Capgo authorization bypass in channel configuration via PostgRESTmediumCVSS 6.5
- CVE-2026-56329: Capgo cross-tenant preview namespace collision in hostname parsingmediumCVSS 6.4
- CVE-2026-56312: Capgo improper authentication in accept_invitation endpointmediumCVSS 6.5
- CVE-2026-56309: Capgo plan bypass via unrestricted attachment upload endpointmediumCVSS 5.4
- CVE-2026-56305: Capgo authentication bypass in password change endpointhighCVSS 8.3
- CVE-2026-56279: Capgo information disclosure in get_orgs_v7 RPC functionhighCVSS 7.5
- CVE-2026-56254: Cap-go capacitor-updater encryption bypass via private key distributionhighCVSS 7
- CVE-2026-56298: Capgo sensitive metadata exposure in app information image uploadmediumCVSS 4.3
- CVE-2026-56293: Capgo improper authorization in transfer_app functionmediumCVSS 5.4
- CVE-2026-56284: Capgo information disclosure in get_total_metrics RPC functionmediumCVSS 5.3
- CVE-2026-56283: Capgo HTML injection in organization settingsmediumCVSS 5.4
- CVE-2026-56250: Capgo arbitrary R2 object deletion via mutable r2_path in app_versionshighCVSS 7.5
- CVE-2026-56246: Capgo broken access control in organization management APIhighCVSS 8.1
- CVE-2026-56226: Capgo unauthenticated data disclosure in get_orgs_v6 RPC functionhighCVSS 7.5
Most severe Capgo vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-88864: Capgo authentication bypass via PostgREST direct write to SSO providerscriticalCVSS 9.1EPSS 0.4%
- CVE-2026-56237: Capgo broken authentication in API key generationcriticalCVSS 9.1
- CVE-2026-56247: Capgo privilege escalation via cross-scope RBAC role assignmenthighCVSS 8.8
- CVE-2026-56230: Capgo BOLA in middlewareKey via x-limited-key-id headerhighCVSS 8.8
- CVE-2026-56232: Capgo authorization bypass in middlewareKey subkey enforcementhighCVSS 8.8
- CVE-2026-56216: Capgo scope escalation via API key creation in functions endpointhighCVSS 8.8
- CVE-2026-56223: Capgo account takeover via cross-domain SSO identity mergehighCVSS 8.7
- CVE-2026-56241: Capgo privilege escalation via stale RBAC demotion recordshighCVSS 8.3
- CVE-2026-56305: Capgo authentication bypass in password change endpointhighCVSS 8.3
- CVE-2026-56233: Capgo path traversal in builder upload proxyhighCVSS 8.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 15 | 0 | |
| 6 Jul 2026 | 25 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 2 | 1 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/capgo.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Capgo vulnerabilities", https://junglewise.ai/threats/vendors/capgo, 26 September 2026.