CVE-2026-56219: Capgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_access_rbac NULL-auth Bypass
Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.getorguseraccessrbac function that allows unauthenticated attackers to retrieve RBAC role bindings and member email addresses. Attackers can exploit improper NULL comparison in the authorization gate to disclose organization membership, roles, and email addresses via the PostgREST RPC endpoint using only a public API key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56219?
The severity of CVE-2026-56219 is high, with a rating of 8.7.
How do I fix CVE-2026-56219?
To fix CVE-2026-56219, upgrade Capgo to version 12.128.2 or later.
What type of vulnerability is CVE-2026-56219?
CVE-2026-56219 is an unauthenticated remote code execution vulnerability due to NULL-auth bypass.
What information can be disclosed due to CVE-2026-56219?
CVE-2026-56219 allows attackers to retrieve role bindings and member email addresses.
Who is affected by CVE-2026-56219?
Users of Capgo prior to version 12.128.2 are affected by CVE-2026-56219.