CVE-2026-56244: Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key
Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on the webhooks table. Attackers can retrieve the webhook secret and forge valid X-Capgo-Signature headers to send authenticated webhook events to configured receivers, breaking webhook authenticity and integrity.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2 - Operational
Revoke/rotate any exposed webhook signing secrets after upgrading to 12.128.2, since non-admin API keys could retrieve webhook signing secrets and forge X-Capgo-Signature headers.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56244?
The severity of CVE-2026-56244 is high with a score of 7.1.
How do I fix CVE-2026-56244?
To fix CVE-2026-56244, ensure that row-level security policies on the webhooks table are properly configured to restrict access to only admin API keys.
What does CVE-2026-56244 disclose?
CVE-2026-56244 discloses webhook signing secrets via non-admin API keys due to insufficient row-level security.
What impact does CVE-2026-56244 have?
The impact of CVE-2026-56244 allows attackers to forge valid X-Capgo-Signature headers and send authenticated webhook events.
Which versions of Capgo are affected by CVE-2026-56244?
CVE-2026-56244 affects Capgo versions prior to 12.128.2.