CVE-2026-100623: Incorrect Authorization in Cap-go capgo.app
CVE-2026-100623 is an authorization vulnerability in Cap-go's capgo.app affecting all versions. The legacy membership table public.org_users is exposed via Supabase PostgREST with row-level security policies that only verify admin rights but do not enforce invitation acceptance or role consistency checks. This allows an authenticated organization admin to directly insert or update membership records, adding any existing user as an admin without following the intended invitation workflow. No patch was available at the time of publication.
AI Analysis
Technical Summary
Cap-go's capgo.app exposes the legacy membership table public.org_users through Supabase PostgREST. The row-level security policies permit organization admins to insert or update rows if they have admin rights, but these policies do not require the target user to have a pending invitation, accept an invite token, or pass role-binding consistency and anti-escalation checks. Consequently, an authenticated admin can directly add any existing public.users account as an active admin member of the organization, bypassing invitation and role-assignment workflows. Testing showed that accounts with no prior access could gain admin rights and read organization and app data after such direct inserts. All versions are affected, and no patch was available at the time of disclosure.
Potential Impact
An authenticated organization admin can escalate privileges by directly adding any existing user as an admin member of the organization without the target user's consent or invitation acceptance. This bypasses intended security workflows, potentially allowing unauthorized access to organization and application data. The vulnerability has a high severity with a CVSS 4.0 score of 8.7, indicating significant impact on confidentiality, integrity, and availability.
Mitigation Recommendations
No patch was available at the time of publication. Organizations should monitor for unauthorized membership changes and restrict admin privileges carefully. Check the vendor advisory for any updates or official fixes. Since this is not a cloud service, remediation depends on vendor patching or configuration changes. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-100623: Incorrect Authorization in Cap-go capgo.app
Description
CVE-2026-100623 is an authorization vulnerability in Cap-go's capgo.app affecting all versions. The legacy membership table public.org_users is exposed via Supabase PostgREST with row-level security policies that only verify admin rights but do not enforce invitation acceptance or role consistency checks. This allows an authenticated organization admin to directly insert or update membership records, adding any existing user as an admin without following the intended invitation workflow. No patch was available at the time of publication.
CVSS v4.0
Score 8.7high
Affected software
Cap-go
capgo.app
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cap-go's capgo.app exposes the legacy membership table public.org_users through Supabase PostgREST. The row-level security policies permit organization admins to insert or update rows if they have admin rights, but these policies do not require the target user to have a pending invitation, accept an invite token, or pass role-binding consistency and anti-escalation checks. Consequently, an authenticated admin can directly add any existing public.users account as an active admin member of the organization, bypassing invitation and role-assignment workflows. Testing showed that accounts with no prior access could gain admin rights and read organization and app data after such direct inserts. All versions are affected, and no patch was available at the time of disclosure.
Potential Impact
An authenticated organization admin can escalate privileges by directly adding any existing user as an admin member of the organization without the target user's consent or invitation acceptance. This bypasses intended security workflows, potentially allowing unauthorized access to organization and application data. The vulnerability has a high severity with a CVSS 4.0 score of 8.7, indicating significant impact on confidentiality, integrity, and availability.
Mitigation Recommendations
No patch was available at the time of publication. Organizations should monitor for unauthorized membership changes and restrict admin privileges carefully. Check the vendor advisory for any updates or official fixes. Since this is not a cloud service, remediation depends on vendor patching or configuration changes. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:31:07.602Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a3f7a7c5410652fd0c
Added to database: 09/26/2026, 13:33:23 UTC
Last enriched: 09/26/2026, 14:18:12 UTC
Last updated: 09/26/2026, 14:47:53 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.