Privilege Escalation Vulnerability in Capgo Affects User Security
CVE-2026-56251

7HIGH

Key Information:

Vendor

Capgo

Status
Vendor
CVE Published:
21 June 2026

What is CVE-2026-56251?

Capgo versions prior to 12.128.2 are susceptible to a vulnerability caused by a broken row-level security policy in the org_users table. This flaw enables authenticated users to elevate their privileges from admin to super_admin, unauthorizedly granting them higher access levels. Exploiting this vulnerability could lead to significant compromises in system security, allowing attackers to manipulate user permissions and potentially gain control over sensitive data.

Affected Version(s)

Capgo 0 < 12.128.2

Capgo 12.128.2

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.