Authorization Bypass in Capgo Affects Role Binding Functionality
CVE-2026-56222
8.6HIGH
What is CVE-2026-56222?
An issue in Capgo versions prior to 12.128.2 allows attackers with admin privileges within one organization to bypass authorization checks in the role binding functionality. Specifically, this vulnerability occurs in the POST /private/role_bindings endpoint, where the system fails to verify the ownership of app_id. As a result, a malicious actor can create role bindings for applications belonging to other organizations, leading to unauthorized access and potential manipulation of sensitive application data.
Affected Version(s)
Capgo 0 < 12.128.2
Capgo 12.128.2
