← Back to search

CVE-2026-100623

8.8 HIGHpublic exploit available

Published 2026-09-26 · Updated 2026-09-28

AI risk analysis

Summary
This flaw allows an authenticated admin to bypass the normal membership workflow and directly add any user as an admin in their organization, potentially granting unauthorized access.
Exploitability
Exploitation is relatively straightforward for an admin with write access to the org_users table, requiring only the ability to insert or update rows.
Blast radius
If exploited, this could lead to unauthorized access and control over the organization's resources, including apps and data.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable direct write access to the org_users table and enforce the existing invite and role-assignment workflow.
auth-bypassrbacweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin rights in the target organization (public.check_min_rights('admin', ...)); they do not require a pending invitation in tmp_users, acceptance of an invite token via /private/accept_invitation, any action by the target user, or the membership/role-consistency and anti-escalation checks enforced by the RBAC role-binding path. As a result, an authenticated user who is an admin of an organization can INSERT or UPDATE org_users rows directly to add any existing public.users account as an active member of that organization with user_right="admin", bypassing the invitation and role-assignment workflow entirely. In testing, an account with no prior access to the organization or its apps could, after such a direct insert, read the organization and app and pass check_min_rights. All versions are affected and no patch was available at the time of publication.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-863

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.