Skip to main content

CVE-2026-100623: Incorrect Authorization in Cap-go capgo.app

0
High
VulnerabilityCVE-2026-100623cvecve-2026-100623
Published: 09/26/2026 (09/26/2026, 13:23:01 UTC)
Source: CVE Database V5
Vendor/Project: Cap-go
Product: capgo.app

Description

CVE-2026-100623 is an authorization vulnerability in Cap-go's capgo.app affecting all versions. The legacy membership table public.org_users is exposed via Supabase PostgREST with row-level security policies that only verify admin rights but do not enforce invitation acceptance or role consistency checks. This allows an authenticated organization admin to directly insert or update membership records, adding any existing user as an admin without following the intended invitation workflow. No patch was available at the time of publication.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

Cap-go

capgo.app

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 14:18:12 UTC

Technical Analysis

Cap-go's capgo.app exposes the legacy membership table public.org_users through Supabase PostgREST. The row-level security policies permit organization admins to insert or update rows if they have admin rights, but these policies do not require the target user to have a pending invitation, accept an invite token, or pass role-binding consistency and anti-escalation checks. Consequently, an authenticated admin can directly add any existing public.users account as an active admin member of the organization, bypassing invitation and role-assignment workflows. Testing showed that accounts with no prior access could gain admin rights and read organization and app data after such direct inserts. All versions are affected, and no patch was available at the time of disclosure.

Potential Impact

An authenticated organization admin can escalate privileges by directly adding any existing user as an admin member of the organization without the target user's consent or invitation acceptance. This bypasses intended security workflows, potentially allowing unauthorized access to organization and application data. The vulnerability has a high severity with a CVSS 4.0 score of 8.7, indicating significant impact on confidentiality, integrity, and availability.

Mitigation Recommendations

No patch was available at the time of publication. Organizations should monitor for unauthorized membership changes and restrict admin privileges carefully. Check the vendor advisory for any updates or official fixes. Since this is not a cloud service, remediation depends on vendor patching or configuration changes. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-26T02:31:07.602Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab7c9a3f7a7c5410652fd0c

Added to database: 09/26/2026, 13:33:23 UTC

Last enriched: 09/26/2026, 14:18:12 UTC

Last updated: 09/26/2026, 14:47:53 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses