Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-56238: Capgo - Unauthenticated Access to Financial and Operational Metrics
CVE-2026-56238
CVE-2026-56238
Summary
A security issue in Capgo allows unauthenticated attackers to view sensitive financial and operational information, including revenue and customer counts. This can happen when an attacker uses the public API key to access the global_stats endpoint. To protect against this, update to Capgo version 12.128.2 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| capgo | capgo | < 12.128.2 |
Original title
Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operatio...
Original description
Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote attackers can query the /rest/v1/global_stats endpoint to expose MRR, total revenue, plan-tier revenue breakdown, customer counts, and operational telemetry.
nvd CVSS3.1
7.5
nvd CVSS4.0
8.7
Vulnerability type
CWE-200
Information Exposure
Published: 12 Jul 2026 · Updated: 20 Jul 2026 · First seen: 12 Jul 2026