Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100623— Capgo Authentication Bypass via Direct PostgREST org_users Table Write

Quick assessment

Affected
Cap-go capgo.app
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Capgo(capgo.app)通过 Supabase PostgREST 直接暴露了传统的成员表 。该表的行级安全策略“允许组织管理员插入”和“允许组织管理员更新”仅验证调用方在目标组织中是否具有管理员权限(即执行 ),而不要求存在待处理的临时用户邀请(位于 表中)、不要求通过 接口接受邀请令牌、不要求目标用户采取任何操作,也不执行由 RBAC 角色绑定路径所强制实施的成员资格/角色一致性检查及权限提升防护机制。 因此,任何作为组织管理员的已认证用户,都可以直接对 表执行 INSERT 或 UPDATE 操作,将

CVSS 8.8 · High EPSS 0.32% · P23
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100623

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Capgo Authentication Bypass via Direct PostgREST org_users Table Write
Source: CVE Program / CVE List V5
Vulnerability Description
Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin rights in the target organization (public.check_min_rights('admin', ...)); they do not require a pending invitation in tmp_users, acceptance of an invite token via /private/accept_invitation, any action by the target user, or the membership/role-consistency and anti-escalation checks enforced by the RBAC role-binding path. As a result, an authenticated user who is an admin of an organization can INSERT or UPDATE org_users rows directly to add any existing public.users account as an active member of that organization with user_right="admin", bypassing the invitation and role-assignment workflow entirely. In testing, an account with no prior access to the organization or its apps could, after such a direct insert, read the organization and app and pass check_min_rights. All versions are affected and no patch was available at the time of publication.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cap-go capgo.app - -

II. Public POCs for CVE-2026-100623

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100623

请登录查看更多情报信息。

Other References for CVE-2026-100623 (1)

Other References for CVE-2026-100623 (1)

Same Patch Batch · Cap-go · 2026-09-26 · 19 CVEs total

CVE-2026-100619 8.8 HIGH Capgo OTA Manifest Poisoning via app_versions.manifest Bypass
CVE-2026-100614 8.8 HIGH Capgo before 12.244.1 Cross-Tenant Image Overwrite via Metadata Worker
CVE-2026-100617 8.8 HIGH Cap-go capgo.app Authorization Bypass via channel_permission_overrides
CVE-2026-100615 8.8 HIGH Cap-go capgo.app before 12.267.1 Privilege Escalation via API Key Rotation
CVE-2026-100618 8.5 HIGH Capgo App Icon Update Privilege Escalation via Service-Role Worker
CVE-2026-100627 8.1 HIGH Capgo bundle promotion API channel RBAC deny override bypass
CVE-2026-100622 7.5 HIGH capgo.app through 12.129.0 Cache Restoration of Deleted Bundles
CVE-2026-100612 7.2 HIGH Capgo SSO Provider ID Authentication Bypass via Incomplete Migration
CVE-2026-100625 7.1 HIGH Capgo Build Upload Proxy Authorization Bypass via TUS Resource
CVE-2026-100611 6.5 MEDIUM Capgo apikey_manager Role Privilege Escalation via Incomplete Role Deny-list
CVE-2026-100629 5.5 MEDIUM Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCH
CVE-2026-100616 5.5 MEDIUM capgo.app Authentication Bypass via PostgREST customer_id Mutation
CVE-2026-100624 5.4 MEDIUM Capgo.app before 12.264.5 Upload Expiry Bypass via build upload
CVE-2026-100613 5.3 MEDIUM capgo.app Authorization Bypass via Stale Channel Permission Overrides
CVE-2026-100628 4.3 MEDIUM capgo.app before 12.128.12 Authentication Bypass via apikey
CVE-2026-100626 4.3 MEDIUM capgo through 12.128.2 IDOR via PUT /app icon endpoint
CVE-2026-100621 4.3 MEDIUM capgo.app Content-Lock Bypass via r2-direct Bundle Mutation
CVE-2026-100620 3.8 LOW Capgo CLI through 7.98.2 Excessive Permissions via Overpermissioned Play Console Service A

IV. Related Vulnerabilities

V. Comments for CVE-2026-100623

No comments yet


Leave a comment