MEDIUM
Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint
Published Jun 22, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.46%
Description
Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /private/role_bindings/:org_id endpoint, unlike the POST and DELETE role_bindings routes, so unauthenticated requests reach the handler instead of being rejected at the middleware layer. The handler still performs its own authorization check and returns Unauthorized, so no direct data exposure occurs; the flaw is inconsistent authentication enforcement across HTTP methods that could enable authorization bypass if the handler logic changes.
Affected products
-
- Version 0StatusaffectedConstraints<12.128.2
- Version 12.128.2StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/Cap-go/capgo/security/advisories/GHSA-6c9f-9v99-26ww exploitvendor-advisory
- https://www.vulncheck.com/advisories/capgo-missing-authentication-middleware-on-get-private-role-bindings-endpoint third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/Cap-go/capgo/security/advisories/GHSA-6c9f-9v99-26ww | exploitvendor-advisory | |
| https://www.vulncheck.com/advisories/capgo-missing-authentication-middleware-on-get-private-role-bindings-endpoint | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jun 22, 2026
Updated Jun 23, 2026
Reserved Jun 20, 2026
Link CVE-2026-56321
CISA Vulnrichment
Updated Jun 23, 2026