CVE-2026-56213: Capgo - Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPC
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsertversionmeta SECURITY DEFINER function exposed via PostgREST RPC, allowing unauthenticated attackers to insert arbitrary rows into versionmeta for any appid. Attackers can exploit this by calling the RPC endpoint with a public anon key to poison storage metrics, causing persistent false data in dashboards and triggering incorrect alerts across victim applications.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56213?
CVE-2026-56213 has a medium severity rating of 5.3.
How do I fix CVE-2026-56213?
To mitigate CVE-2026-56213, update Capgo to version 12.128.2 or later, which addresses the authorization bypass.
What does CVE-2026-56213 exploit?
CVE-2026-56213 exploits an authorization bypass vulnerability in the public.upsert_version_meta function allowing unauthenticated access.
What type of attack is associated with CVE-2026-56213?
CVE-2026-56213 is associated with unauthenticated cross-tenant metrics poisoning attacks.
Which versions of Capgo are affected by CVE-2026-56213?
CVE-2026-56213 affects all versions of Capgo prior to 12.128.2.