Unrated severityNVD Advisory· Published Jun 20, 2026
Capgo - Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC
CVE-2026-56214
Description
Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that allows unauthenticated attackers to enumerate organizations and disclose billing status using the public sb_publishable key. Attackers can invoke these endpoints to determine organization existence via distinguishable return values and identify paying customers for targeted profiling.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
2- Capgo: 21 CVEs Disclosed Together — Unauthenticated Cross-Tenant Bugs and Scope Escalation Lead the BatchVypr Intelligence · Jun 20, 2026
- Capgo: Ten Vulnerabilities Disclosed Together, Including Scope Escalation and Unauthenticated Cross-Tenant BugsVypr Intelligence · Jun 20, 2026