Authorization Bypass in Cap-go Product Affects Supabase API Functionality
CVE-2026-56235
6.9MEDIUM
What is CVE-2026-56235?
The Cap-go software before version 12.128.2 has a significant security flaw that allows an attacker to bypass authorization controls across several RPC functions within Supabase. This vulnerability exposes critical telemetry data, enabling an unauthenticated individual to exploit the public Supabase API key for unauthorized access. Attackers can leverage this oversight to reveal cross-tenant usage metrics, enumerate application IDs, and validate the existence of organizations, thereby creating serious risks to organizational privacy and data integrity.
Affected Version(s)
capgo 0 < 12.128.2
capgo 12.128.2
