CVE-2026-56220: Capgo - Unauthorized Manifest Insertion via Read-Only Org Member
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows read-only org members to insert OTA manifest rows. Attackers with read-only org access can inject malicious manifest entries with arbitrary s3path values that are served to devices via the unauthenticated /updates endpoint, enabling OTA metadata poisoning and potential malicious asset delivery.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2 - Configuration
Update the public.manifest INSERT authorization so read-only org members cannot insert OTA manifest rows with arbitrary s3_path values.
Capgo public.manifest INSERT policy authorization checks for INSERT = restrict to authorized write roles only (prevent read-only org members from inserting OTA manifest rows)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56220?
The severity of CVE-2026-56220 is rated high with a score of 7.1.
How do I fix CVE-2026-56220?
To fix CVE-2026-56220, upgrade to Capgo version 12.128.2 or later where the authorization bypass vulnerability has been patched.
What type of vulnerability is CVE-2026-56220?
CVE-2026-56220 is an authorization bypass vulnerability that allows unauthorized insertion of OTA manifest rows.
Who is affected by CVE-2026-56220?
CVE-2026-56220 affects users of Capgo versions prior to 12.128.2, particularly read-only org members.
What are the potential consequences of CVE-2026-56220?
The consequences of CVE-2026-56220 include the possibility for attackers to inject malicious manifest entries that can be served to devices.