Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-56222: Capgo - Unauthorized Access to Other Organizations' Apps

CVE-2026-56222 GHSA-5r52-m8r9-7f8x
Summary

An attacker with admin privileges in one organization can access and modify apps from other organizations using Capgo before version 12.128.2. This is a serious issue because it allows unauthorized access to sensitive data. Update to version 12.128.2 or later to fix this vulnerability.

Original title
Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings
Original description
Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify app_id ownership during app-scoped role binding creation. An attacker with administrative privileges in one organization can create role bindings targeting applications owned by other organizations, enabling unauthorized read and modification of victim applications.
osv CVSS4.0 9.4
Vulnerability type
CWE-639 Authorization Bypass Through User-Controlled Key
Published: 23 Jun 2026 · Updated: 8 Jul 2026 · First seen: 8 Jul 2026