Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-56339: Observable Discrepancy in Cap-go capgoCVE-2026-56339
0

Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. The function returns distinct error messages (NO_ORG vs NO_RIGHTS) when called with only a publishable API key, enabling attackers to discover valid organization IDs and increase the attack surface for targeted phishing or social engineering campaigns.

Join the discussion
Capgo versions before 12.128.2 have a scope isolation vulnerability in the POST /webhooks/test endpoint. (CVE-2026-56252)CVE-2026-56252
0

Capgo versions before 12.128.2 have a scope isolation vulnerability in the POST /webhooks/test endpoint. This flaw allows app-scoped API keys to invoke organization-scoped webhook operations, bypassing the intended authorization checks that limit API keys to their declared app boundaries. Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary organization webhooks outside their app scope.

Join the discussion
Capgo versions before 12.128.2 have an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint. (CVE-2026-56238)CVE-2026-56238
0

Capgo versions before 12.128.2 have an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint. This flaw allows unauthenticated attackers to access sensitive financial and operational metrics by using only the public API key. Attackers can query the /rest/v1/global_stats endpoint to retrieve data such as monthly recurring revenue (MRR), total revenue, plan-tier revenue breakdown, customer counts, and operational telemetry.

Join the discussion
Capgo versions before 12.128.2 have a privilege escalation vulnerability where users demoted from super_admin roles retain access to certain RPCs… (CVE-2026-56241)CVE-2026-56241
0

Capgo versions before 12.128.2 have a privilege escalation vulnerability where users demoted from super_admin roles retain access to certain RPCs due to stale user rights not being cleared. This allows attackers to enumerate and delete non-compliant bundles across the organization indefinitely.

Join the discussion
Capgo versions before 12.128.2 have an information disclosure vulnerability in an unauthenticated endpoint (/private/sso/check-domain) that reveals… (CVE-2026-56336)CVE-2026-56336
0

Capgo versions before 12.128.2 have an information disclosure vulnerability in an unauthenticated endpoint (/private/sso/check-domain) that reveals internal organization and provider identifiers. This allows attackers to enumerate email domains and map them to organization UUIDs and SSO provider IDs, facilitating reconnaissance against Capgo tenants.

Join the discussion
Capgo versions before 12.128.2 have a vulnerability that allows changing the account email address without requiring the current password or… (CVE-2026-56308)CVE-2026-56308
0

Capgo versions before 12.128.2 have a vulnerability that allows changing the account email address without requiring the current password or verification of the existing email. An attacker with access to a valid session cookie or authenticated browser session can exploit this to change the email address, potentially taking control of account recovery and bypassing multi-factor authentication protections.

Join the discussion
Capgo versions before 12.128.2 have a SQL injection vulnerability in the POST /private/admin_stats endpoint. (CVE-2026-56281)CVE-2026-56281
0

Capgo versions before 12.128.2 have a SQL injection vulnerability in the POST /private/admin_stats endpoint. The vulnerability arises because the limit parameter from the request body is not validated and is directly interpolated into SQL queries used by the Cloudflare Analytics Engine. This allows an attacker with platform admin credentials to inject SQL fragments, potentially enumerating dataset schemas, extracting analytics data, or causing denial-of-service against the analytics backend.

Join the discussion
Capgo before version 12.128.2 has a vulnerability in its SSO prelink endpoint that allows enterprise administrators with org.update_settings… (CVE-2026-56313)CVE-2026-56313
0

Capgo before version 12.128.2 has a vulnerability in its SSO prelink endpoint that allows enterprise administrators with org.update_settings permission and an active SSO provider to delete password identities of users in other organizations. This cross-organization account disruption forces affected users to either use the attacker's SSO provider or go through password reset recovery. The vulnerability impacts email-based authentication for users matching the attacker's SSO email domain.

Join the discussion
Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted… (CVE-2026-56240)CVE-2026-56240
0

Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin hot-path plan_valid expression and the authoritative billing gate to gain continued access to /updates, /stats, /channel_self, and attachment upload endpoints after credit depletion.

Join the discussion
Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and… (CVE-2026-56303)CVE-2026-56303
0

Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to retrieve sensitive API key metadata including user_id, mode, org scoping, and expiration details when supplied a valid key value.

Join the discussion

Showing 1 to 10 of 17 results

Filters:Package: pkg:github/capgo
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses