SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-56217

MEDIUM · CVSS 4.3 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A policy bypass vulnerability in Capgo versions prior to 12.128.2 allows attackers with app-scoped API keys to downgrade encrypted bundles to an unencrypted state by manipulating the app_versions table through PostgREST. This exploitation can compromise OTA security controls, making it critical for organizations using Capgo to prioritize patching to maintain the integrity of their application security. Users managing sensitive data or relying on encrypted bundles should address this vulnerability promptly to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56217
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%

Original NVD Description

Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped API keys to downgrade encrypted bundles to non-encrypted state. Attackers with app-scoped all API keys can directly update the app_versions table via PostgREST to clear session_key and key_id fields, bypassing organization-enforced encrypted-bundle policies and weakening OTA security controls.