{"schema_version":1,"title":"Capgo vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 98 vulnerabilities in Capgo: 7 in the last 7 days and 49 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100629, was published on 26 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/capgo","json_url":"https://junglewise.ai/threats/vendors/capgo.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/capgo","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":44,"all_time":98,"critical":2,"exploited":0,"last_7_days":7,"last_30_days":9,"last_90_days":49,"last_365_days":98},"latest":[{"cve":"CVE-2026-100629","cvss":5.5,"slug":"cve-2026-100629-capgo-capgo-app-backend-before-12-127-5-contains-an","title":"Capgo backend authorization flaw in role bindings PATCH endpoint","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:44.117+00:00","url":"https://junglewise.ai/threats/cve-2026-100629-capgo-capgo-app-backend-before-12-127-5-contains-an"},{"cve":"CVE-2026-100625","cvss":7.1,"slug":"cve-2026-100625-capgo-capgo-app-exposes-a-native-build-tus-upload-proxy-supabase","title":"Capgo build upload proxy authorization bypass via TUS resource","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:43.567+00:00","url":"https://junglewise.ai/threats/cve-2026-100625-capgo-capgo-app-exposes-a-native-build-tus-upload-proxy-supabase"},{"cve":"CVE-2026-100624","cvss":5.4,"slug":"cve-2026-100624-capgo-app-before-12-264-5-does-not-enforce-upload-expiry-or","title":"Capgo.app build upload proxy session expiry bypass","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:43.43+00:00","url":"https://junglewise.ai/threats/cve-2026-100624-capgo-app-before-12-264-5-does-not-enforce-upload-expiry-or"},{"cve":"CVE-2026-100619","cvss":8.8,"slug":"cve-2026-100619-capgo-capgo-app-blocks-direct-user-inserts-into-the-public","title":"Capgo manifest poisoning via app_versions bypass","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:42.74+00:00","url":"https://junglewise.ai/threats/cve-2026-100619-capgo-capgo-app-blocks-direct-user-inserts-into-the-public"},{"cve":"CVE-2026-100618","cvss":8.5,"slug":"cve-2026-100618-capgo-capgo-app-is-affected-by-an-authorization-flaw-in-the-app","title":"Capgo app icon update authorization bypass in worker","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:42.6+00:00","url":"https://junglewise.ai/threats/cve-2026-100618-capgo-capgo-app-is-affected-by-an-authorization-flaw-in-the-app"},{"cve":"CVE-2026-100612","cvss":7.2,"slug":"cve-2026-100612-capgo-capgo-app-through-version-12-261-0-contains-an-incomplete","title":"Capgo access control bypass in SSO provider configuration","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:41.753+00:00","url":"https://junglewise.ai/threats/cve-2026-100612-capgo-capgo-app-through-version-12-261-0-contains-an-incomplete"},{"cve":"CVE-2026-100611","cvss":6.5,"slug":"cve-2026-100611-capgo-capgo-app-backend-versions-12-261-0-improperly-restricts","title":"Capgo apikey_manager role privilege escalation via incomplete role deny-list","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:41.61+00:00","url":"https://junglewise.ai/threats/cve-2026-100611-capgo-capgo-app-backend-versions-12-261-0-improperly-restricts"},{"cve":"CVE-2026-88864","cvss":9.1,"epss":0.0037,"slug":"cve-2026-88864-capgo-authentication-bypass-via-postgrest-direct-write-to-sso","title":"Capgo authentication bypass via PostgREST direct write to SSO providers","severity":"critical","exploited":false,"published_at":"2026-09-10T14:17:12.187+00:00","url":"https://junglewise.ai/threats/cve-2026-88864-capgo-authentication-bypass-via-postgrest-direct-write-to-sso"},{"cve":"CVE-2026-88860","cvss":6.3,"epss":0.0027,"slug":"cve-2026-88860-capgo-authorization-bypass-via-stale-channel-permission-overrides","title":"Capgo authorization bypass via stale channel permission overrides","severity":"medium","exploited":false,"published_at":"2026-09-10T14:17:11.527+00:00","url":"https://junglewise.ai/threats/cve-2026-88860-capgo-authorization-bypass-via-stale-channel-permission-overrides"},{"cve":"CVE-2026-56336","cvss":5.3,"slug":"cve-2026-56336-capgo-information-disclosure-in-sso-check-domain-endpoint","title":"Capgo information disclosure in SSO check-domain endpoint","severity":"medium","exploited":false,"published_at":"2026-07-12T12:16:45.837+00:00","url":"https://junglewise.ai/threats/cve-2026-56336-capgo-information-disclosure-in-sso-check-domain-endpoint"},{"cve":"CVE-2026-56313","cvss":8.1,"slug":"cve-2026-56313-capgo-improper-authorization-in-sso-prelink-endpoint","title":"Capgo improper authorization in SSO prelink endpoint","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:45.703+00:00","url":"https://junglewise.ai/threats/cve-2026-56313-capgo-improper-authorization-in-sso-prelink-endpoint"},{"cve":"CVE-2026-56308","cvss":7.3,"slug":"cve-2026-56308-capgo-insufficient-authentication-in-email-change-endpoint","title":"Capgo insufficient authentication in email change endpoint","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:45.567+00:00","url":"https://junglewise.ai/threats/cve-2026-56308-capgo-insufficient-authentication-in-email-change-endpoint"},{"cve":"CVE-2026-56281","cvss":3.8,"slug":"cve-2026-56281-capgo-sql-injection-in-admin-stats-endpoint","title":"Capgo SQL injection in admin_stats endpoint","severity":"low","exploited":false,"published_at":"2026-07-12T12:16:45.433+00:00","url":"https://junglewise.ai/threats/cve-2026-56281-capgo-sql-injection-in-admin-stats-endpoint"},{"cve":"CVE-2026-56252","cvss":5.4,"slug":"cve-2026-56252-capgo-incorrect-authorization-in-webhook-test-endpoint","title":"Capgo incorrect authorization in webhook test endpoint","severity":"medium","exploited":false,"published_at":"2026-07-12T12:16:44.867+00:00","url":"https://junglewise.ai/threats/cve-2026-56252-capgo-incorrect-authorization-in-webhook-test-endpoint"},{"cve":"CVE-2026-56241","cvss":8.3,"slug":"cve-2026-56241-capgo-privilege-escalation-via-stale-rbac-demotion-records","title":"Capgo privilege escalation via stale RBAC demotion records","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:44.73+00:00","url":"https://junglewise.ai/threats/cve-2026-56241-capgo-privilege-escalation-via-stale-rbac-demotion-records"},{"cve":"CVE-2026-56238","cvss":7.5,"slug":"cve-2026-56238-capgo-information-disclosure-in-supabase-postgrest-global-stats","title":"Capgo information disclosure in Supabase PostgREST global_stats endpoint","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:44.587+00:00","url":"https://junglewise.ai/threats/cve-2026-56238-capgo-information-disclosure-in-supabase-postgrest-global-stats"},{"cve":"CVE-2026-56303","cvss":7.5,"slug":"cve-2026-56303-capgo-information-disclosure-in-find-apikey-by-value-rpc-function","title":"Capgo information disclosure in find_apikey_by_value RPC function","severity":"high","exploited":false,"published_at":"2026-07-11T14:16:21.82+00:00","url":"https://junglewise.ai/threats/cve-2026-56303-capgo-information-disclosure-in-find-apikey-by-value-rpc-function"},{"cve":"CVE-2026-56240","cvss":4.3,"slug":"cve-2026-56240-capgo-billing-authorization-bypass-in-plan-valid-calculation","title":"Capgo billing authorization bypass in plan_valid calculation","severity":"medium","exploited":false,"published_at":"2026-07-11T14:16:20.707+00:00","url":"https://junglewise.ai/threats/cve-2026-56240-capgo-billing-authorization-bypass-in-plan-valid-calculation"},{"cve":"CVE-2026-56335","cvss":6.5,"slug":"cve-2026-56335-capgo-authorization-bypass-in-channel-configuration-via-postgrest","title":"Capgo authorization bypass in channel configuration via PostgREST","severity":"medium","exploited":false,"published_at":"2026-07-10T15:16:42.88+00:00","url":"https://junglewise.ai/threats/cve-2026-56335-capgo-authorization-bypass-in-channel-configuration-via-postgrest"},{"cve":"CVE-2026-56329","cvss":6.4,"slug":"cve-2026-56329-capgo-cross-tenant-preview-namespace-collision-in-hostname","title":"Capgo cross-tenant preview namespace collision in hostname parsing","severity":"medium","exploited":false,"published_at":"2026-07-10T15:16:42.727+00:00","url":"https://junglewise.ai/threats/cve-2026-56329-capgo-cross-tenant-preview-namespace-collision-in-hostname"},{"cve":"CVE-2026-56312","cvss":6.5,"slug":"cve-2026-56312-capgo-improper-authentication-in-accept-invitation-endpoint","title":"Capgo improper authentication in accept_invitation endpoint","severity":"medium","exploited":false,"published_at":"2026-07-10T15:16:42.587+00:00","url":"https://junglewise.ai/threats/cve-2026-56312-capgo-improper-authentication-in-accept-invitation-endpoint"},{"cve":"CVE-2026-56309","cvss":5.4,"slug":"cve-2026-56309-capgo-plan-bypass-via-unrestricted-attachment-upload-endpoint","title":"Capgo plan bypass via unrestricted attachment upload endpoint","severity":"medium","exploited":false,"published_at":"2026-07-10T15:16:42.44+00:00","url":"https://junglewise.ai/threats/cve-2026-56309-capgo-plan-bypass-via-unrestricted-attachment-upload-endpoint"},{"cve":"CVE-2026-56305","cvss":8.3,"slug":"cve-2026-56305-capgo-authentication-bypass-in-password-change-endpoint","title":"Capgo authentication bypass in password change endpoint","severity":"high","exploited":false,"published_at":"2026-07-10T15:16:42.3+00:00","url":"https://junglewise.ai/threats/cve-2026-56305-capgo-authentication-bypass-in-password-change-endpoint"},{"cve":"CVE-2026-56279","cvss":7.5,"slug":"cve-2026-56279-capgo-information-disclosure-in-get-orgs-v7-rpc-function","title":"Capgo information disclosure in get_orgs_v7 RPC function","severity":"high","exploited":false,"published_at":"2026-07-10T15:16:42.157+00:00","url":"https://junglewise.ai/threats/cve-2026-56279-capgo-information-disclosure-in-get-orgs-v7-rpc-function"},{"cve":"CVE-2026-56254","cvss":7,"slug":"cve-2026-56254-cap-go-capacitor-updater-encryption-bypass-via-private-key","title":"Cap-go capacitor-updater encryption bypass via private key distribution","severity":"high","exploited":false,"published_at":"2026-07-10T15:16:41.81+00:00","url":"https://junglewise.ai/threats/cve-2026-56254-cap-go-capacitor-updater-encryption-bypass-via-private-key"}],"vendor":{"hub":true,"name":"Capgo","slug":"capgo","homepage":"https://capgo.app/","description":"A provider of cloud-based update and deployment services for Capacitor and Ionic applications.","url":"https://junglewise.ai/threats/vendors/capgo"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":15},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":25},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":7}],"most_severe":[{"cve":"CVE-2026-88864","cvss":9.1,"epss":0.0037,"slug":"cve-2026-88864-capgo-authentication-bypass-via-postgrest-direct-write-to-sso","title":"Capgo authentication bypass via PostgREST direct write to SSO providers","severity":"critical","exploited":false,"published_at":"2026-09-10T14:17:12.187+00:00","url":"https://junglewise.ai/threats/cve-2026-88864-capgo-authentication-bypass-via-postgrest-direct-write-to-sso"},{"cve":"CVE-2026-56237","cvss":9.1,"slug":"cve-2026-56237-capgo-broken-authentication-in-api-key-generation","title":"Capgo broken authentication in API key generation","severity":"critical","exploited":false,"published_at":"2026-06-24T13:16:33.467+00:00","url":"https://junglewise.ai/threats/cve-2026-56237-capgo-broken-authentication-in-api-key-generation"},{"cve":"CVE-2026-100619","cvss":8.8,"slug":"cve-2026-100619-capgo-capgo-app-blocks-direct-user-inserts-into-the-public","title":"Capgo manifest poisoning via app_versions bypass","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:42.74+00:00","url":"https://junglewise.ai/threats/cve-2026-100619-capgo-capgo-app-blocks-direct-user-inserts-into-the-public"},{"cve":"CVE-2026-56247","cvss":8.8,"slug":"cve-2026-56247-capgo-privilege-escalation-via-cross-scope-rbac-role-assignment","title":"Capgo privilege escalation via cross-scope RBAC role assignment","severity":"high","exploited":false,"published_at":"2026-06-30T23:17:29.107+00:00","url":"https://junglewise.ai/threats/cve-2026-56247-capgo-privilege-escalation-via-cross-scope-rbac-role-assignment"},{"cve":"CVE-2026-56230","cvss":8.8,"slug":"cve-2026-56230-capgo-bola-in-middlewarekey-via-x-limited-key-id-header","title":"Capgo BOLA in middlewareKey via x-limited-key-id header","severity":"high","exploited":false,"published_at":"2026-06-30T23:17:28.853+00:00","url":"https://junglewise.ai/threats/cve-2026-56230-capgo-bola-in-middlewarekey-via-x-limited-key-id-header"},{"cve":"CVE-2026-56232","cvss":8.8,"slug":"cve-2026-56232-capgo-authorization-bypass-in-middlewarekey-subkey-enforcement","title":"Capgo authorization bypass in middlewareKey subkey enforcement","severity":"high","exploited":false,"published_at":"2026-06-24T13:16:33.327+00:00","url":"https://junglewise.ai/threats/cve-2026-56232-capgo-authorization-bypass-in-middlewarekey-subkey-enforcement"},{"cve":"CVE-2026-56216","cvss":8.8,"slug":"cve-2026-56216-capgo-scope-escalation-via-api-key-creation-in-functions-endpoint","title":"Capgo scope escalation via API key creation in functions endpoint","severity":"high","exploited":false,"published_at":"2026-06-20T01:16:16.97+00:00","url":"https://junglewise.ai/threats/cve-2026-56216-capgo-scope-escalation-via-api-key-creation-in-functions-endpoint"},{"cve":"CVE-2026-56223","cvss":8.7,"slug":"cve-2026-56223-capgo-account-takeover-via-cross-domain-sso-identity-merge","title":"Capgo account takeover via cross-domain SSO identity merge","severity":"high","exploited":false,"published_at":"2026-06-24T13:16:33.067+00:00","url":"https://junglewise.ai/threats/cve-2026-56223-capgo-account-takeover-via-cross-domain-sso-identity-merge"},{"cve":"CVE-2026-100618","cvss":8.5,"slug":"cve-2026-100618-capgo-capgo-app-is-affected-by-an-authorization-flaw-in-the-app","title":"Capgo app icon update authorization bypass in worker","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:42.6+00:00","url":"https://junglewise.ai/threats/cve-2026-100618-capgo-capgo-app-is-affected-by-an-authorization-flaw-in-the-app"},{"cve":"CVE-2026-56241","cvss":8.3,"slug":"cve-2026-56241-capgo-privilege-escalation-via-stale-rbac-demotion-records","title":"Capgo privilege escalation via stale RBAC demotion records","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:44.73+00:00","url":"https://junglewise.ai/threats/cve-2026-56241-capgo-privilege-escalation-via-stale-rbac-demotion-records"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"Capgo","slug":"capgo","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/capgo"}]}