CVE-2026-56243: Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane
Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforcehashedapikeys being enabled. Attackers can bypass org-level hashed-key enforcement by sending plaintext API keys directly to the PostgREST/RLS plane to access protected resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56243?
The severity of CVE-2026-56243 is rated high with a score of 8.1.
How do I fix CVE-2026-56243?
To fix CVE-2026-56243, upgrade to Capgo version 12.128.2 or later.
What impact does CVE-2026-56243 have on security?
CVE-2026-56243 allows attackers to bypass hashed API key enforcement, potentially leading to unauthorized access.
Which software is affected by CVE-2026-56243?
CVE-2026-56243 affects Capgo versions before 12.128.2.
Can CVE-2026-56243 be exploited remotely?
Yes, CVE-2026-56243 can be exploited remotely as it involves API calls.