Medium severity6.5NVD Advisory· Published Jun 19, 2026· Updated Jun 22, 2026
CVE-2026-56079
CVE-2026-56079
Description
Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to access other tenants' webhook secrets and delivery logs. Attackers can query the webhooks and webhook_deliveries endpoints to exfiltrate HMAC signing secrets and delivery payloads, enabling forged webhook events against victim organizations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
2- Capgo: 21 CVEs Disclosed Together — Unauthenticated Cross-Tenant Bugs and Scope Escalation Lead the BatchVypr Intelligence · Jun 20, 2026
- Capgo: Ten Vulnerabilities Disclosed Together, Including Scope Escalation and Unauthenticated Cross-Tenant BugsVypr Intelligence · Jun 20, 2026