Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-56222: Capgo - Unauthorized Access to Other Organizations' Apps
CVE-2026-56222
GHSA-5r52-m8r9-7f8x
Summary
An attacker with admin privileges in one organization can access and modify apps from other organizations using Capgo before version 12.128.2. This is a serious issue because it allows unauthorized access to sensitive data. Update to version 12.128.2 or later to fix this vulnerability.
Original title
Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings
Original description
Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify app_id ownership during app-scoped role binding creation. An attacker with administrative privileges in one organization can create role bindings targeting applications owned by other organizations, enabling unauthorized read and modification of victim applications.
osv CVSS4.0
9.4
Vulnerability type
CWE-639
Authorization Bypass Through User-Controlled Key
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56222... Vendor Advisory
- https://github.com/Cap-go/capgo/security/advisories/GHSA-5r52-m8r9-7f8x Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56222 Vendor Advisory
- https://www.vulncheck.com/advisories/capgo-cross-organization-app-takeover-via-m... Vendor Advisory
Published: 23 Jun 2026 · Updated: 8 Jul 2026 · First seen: 8 Jul 2026