SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-56241

HIGH · CVSS 8.3 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-12 · Last synced 2026-08-11

CyberRota Analysis

AI-Generated

A privilege escalation vulnerability in Capgo versions prior to 12.128.2 allows demoted super_admin users to retain unauthorized access to critical RPCs, enabling them to enumerate and delete non-compliant bundles across the organization. This flaw arises from the failure to clear the stale user rights associated with role changes. Organizations using Capgo should prioritize patching this vulnerability to prevent potential exploitation and data loss.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-56241
Severity
HIGH
CVSS
8.3
EPSS
0.21%

Original NVD Description

Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared during role binding deletion. Attackers can exploit this by maintaining a previously granted super_admin role to enumerate and bulk delete non-compliant bundles across the entire organization indefinitely.