Unrated severityNVD Advisory· Published Jun 24, 2026
Capgo - Authorization Bypass in App Ownership Transfer via Direct PostgREST Update
CVE-2026-56257
Description
Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() workflow and creating split-brain ownership. Attackers can directly update apps.owner_org while leaving app_versions.owner_org unchanged, enabling old-org keys to retain access to version data while new-org keys control the app record.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-v9jp-r5wh-qqcpmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-authorization-bypass-in-app-ownership-transfer-via-direct-postgrest-updatemitrethird-party-advisory
News mentions
0No linked articles in our index yet.