CVE-2026-56247: Capgo - Privilege Escalation via Cross-Scope RBAC Role Assignment
Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compatibility, including to pending invitees. Attackers can pre-seed malformed high-privilege bindings that survive invite acceptance, enabling accepted low-privilege users to perform unauthorized privileged app actions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2 - Compensating control
Until upgrading, restrict the ability of org admins to assign app-scoped RBAC roles that lack validated org/app role-scope compatibility, especially for users with pending invites.
Event History
Frequently Asked Questions
What is the risk level of CVE-2026-56247?
The risk level of CVE-2026-56247 is 79.
What is the severity score for CVE-2026-56247?
The severity score for CVE-2026-56247 is high at 8.7.
How can I fix CVE-2026-56247?
To fix CVE-2026-56247, ensure that org admins cannot assign app-scoped roles without validating role scope compatibility.
What type of vulnerability is CVE-2026-56247?
CVE-2026-56247 is a privilege escalation vulnerability.
Which software is affected by CVE-2026-56247?
CVE-2026-56247 affects Capgo versions prior to 12.128.2.