Improper Access Control in Capgo Affects User Privacy
CVE-2026-56253
8.7HIGH
What is CVE-2026-56253?
Capgo versions prior to 12.128.2 are vulnerable to an improper access control flaw in the public.get_org_members RPC function. This flaw allows unauthenticated attackers to exploit the system using just the public sb_publishable_* key alongside an organization UUID. By invoking this endpoint, attackers can gain access to sensitive information about organization members, including email addresses, user IDs, roles, and pending invitations, thereby posing a significant risk to member privacy.
Affected Version(s)
Capgo 0 < 12.128.2
Capgo 12.128.2
