CVE-2026-56243
Capgo
Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enabled. Attackers can bypass org-level hashed-key enforcement by sending plaintext API keys directly to the PostgREST/RLS plane to access protected resources.
- CVSS
- 8.6
- EPSS
- 0.27% 19.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.23