Cross-Tenant Authorization Bypass in Capgo Product by Capgo
CVE-2026-56079
7.1HIGH
What is CVE-2026-56079?
A cross-tenant authorization bypass vulnerability has been identified in Capgo prior to version 12.128.2, which affects the PostgREST endpoints. Exploiting this vulnerability allows attackers utilizing organization-scoped read API keys to gain unauthorized access to webhook secrets and delivery logs belonging to other tenants. Through queries to webhooks and webhook_deliveries endpoints, attackers can potentially exfiltrate sensitive HMAC signing secrets and delivery payloads, facilitating the creation of forged webhook events targeted at unsuspecting organizations.
Affected Version(s)
Capgo 0 < 12.128.2
Capgo 12.128.2
