CVE-2026-56257: Capgo - Authorization Bypass in App Ownership Transfer via Direct PostgREST Update
Capgo before 12.128.2 allows direct patching of public.apps.ownerorg through PostgREST, bypassing the transferapp() workflow and creating split-brain ownership. Attackers can directly update apps.ownerorg while leaving appversions.ownerorg unchanged, enabling old-org keys to retain access to version data while new-org keys control the app record.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56257?
CVE-2026-56257 has a high severity rating of 7.1.
How do I fix CVE-2026-56257?
To remediate CVE-2026-56257, update Capgo to version 12.128.3 or later.
What does CVE-2026-56257 exploit?
CVE-2026-56257 exploits an authorization bypass in the app ownership transfer process via direct updates to PostgREST.
What can an attacker do using CVE-2026-56257?
An attacker can directly update the owner_org of an app, which can lead to split-brain ownership and access issues.
Which version of Capgo is affected by CVE-2026-56257?
Capgo versions prior to 12.128.2 are affected by CVE-2026-56257.