OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100619

HIGH · CVSS 8.8 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated users with specific API key permissions to bypass row-level security restrictions and manipulate the public.manifest table in Capgo. This can lead to OTA manifest poisoning, where attackers can serve malicious updates to clients via a trusted service role, potentially compromising the integrity of the application. Organizations using Capgo should prioritize addressing this issue, especially those with app-scoped upload/write permissions, as all versions are affected and no patch is currently available.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100619
Severity
HIGH
CVSS
8.8
EPSS
0.32%

Original NVD Description

Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-scoped upload/write/all API key (upload+ rights) or an authenticated user with write+ rights on an app can update public.app_versions.manifest on a version whose storage_provider is 'r2-direct', which is not covered by the bundle content-lock check. The on_version_update async worker trusts record.manifest and, using the service-role Supabase client, inserts the attacker-controlled file_name, file_hash, and s3_path into public.manifest before clearing app_versions.manifest. When a channel points to the crafted version, the /updates endpoint returns the service-role-created manifest entry as a client-facing download_url, enabling OTA manifest poisoning through a trusted async worker path. All versions are affected; no patch was available at the time of publication.