
CVE-2026-56079 Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to access other tenants' … https://www.cve.org/CVERecord?id=CVE-2026-56079
Post summary
The text announces CVE-2026-56079, revealing a cross‑tenant authorization bypass in Capgo’s PostgREST endpoints that allows org‑scoped read API keys to access data from other tenants.

