CVE-2026-56244 Details
Description
Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on the webhooks table. Attackers can retrieve the webhook secret and forge valid X-Capgo-Signature headers to send authenticated webhook events to configured receivers, breaking webhook authenticity and integrity.
A vulnerability in Capgo versions prior to 12.128.2 allows non-admin API keys to access webhook signing secrets through the Supabase REST API. This issue arises from inadequate row-level security policies on the webhooks table. By exploiting this vulnerability, attackers can retrieve the webhook secret and create valid X-Capgo-Signature headers, enabling them to send authenticated webhook events to designated receivers. This manipulation undermines the authenticity and integrity of the webhooks.
Users are advised to update to Capgo version 12.128.2 or later. After updating, rotate existing webhook secrets to ensure that any previously exposed secrets are no longer valid.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cap-go/capgo/security/advisories/GHSA-qrrx-x3qf-x87v | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/Cap-go/capgo/security/advisories/GHSA-qrrx-x3qf-x87v | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/capgo-webhook-signing-secret-disclosure-via-non-admin-api-key | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Capgo | < 12.128.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | New CVE Received | [email protected] |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
Volerion