Unrated severityNVD Advisory· Published Jun 21, 2026
Capgo - Privilege Escalation via Broken Row Level Security in org_users
CVE-2026-56251
Description
Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users to elevate privileges from admin to super_admin. Attackers can exploit the insufficient RLS enforcement to gain unauthorized super_admin access and compromise system security.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-9xqh-f26v-9c9hmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-privilege-escalation-via-broken-row-level-security-in-org-usersmitrethird-party-advisory
News mentions
0No linked articles in our index yet.