PT-2026-51040 · Cap Go · Cap-Go

Judel777

·

Published

2026-06-19

·

Updated

2026-06-19

·

CVE-2026-56082

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description Improper access control exists in the SECURITY DEFINER PostgREST RPC function public.record build time(). This function is granted to the anon role and can be called using only the public Supabase publishable sb publishable * anon key. An unauthenticated attacker can insert rows into public.build logs for arbitrary organizations. Since the function utilizes ON CONFLICT (build id, org id) DO UPDATE, an attacker can overwrite existing usage and billing records by reusing the same build id for a target organization. This allows for cross-tenant tampering of billing build logs and a financial-impact denial of service by inflating billable build time.
Recommendations Update to version 12.128.2 or later.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56082

Affected Products

Cap-Go