PT-2026-51037 · Cap Go · Cap-Go
Judel777
·
Published
2026-06-19
·
Updated
2026-06-19
·
CVE-2026-56079
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
A cross-tenant authorization bypass exists in PostgREST endpoints. This issue allows API keys with organization-level read permissions to access webhook secrets and delivery logs belonging to other tenants. An attacker can query the "/webhooks" and "/webhook deliveries" endpoints to exfiltrate HMAC (Hash-based Message Authentication Code) signing secrets and delivery payloads, which can be used to forge webhook events against victim organizations.
Recommendations
Update to version 12.128.2 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go