Description
Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote attackers can query the /rest/v1/global_stats endpoint to expose MRR, total revenue, plan-tier revenue breakdown, customer counts, and operational telemetry.
Published: 2026-07-12
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Capgo before version 12.128.2 has an information disclosure vulnerability in its Supabase PostgREST global_stats endpoint. The flaw allows unauthenticated attackers to read sensitive financial and operational metrics such as monthly recurring revenue, total revenue, plan‑tier revenue breakdown, customer counts, and operational telemetry by sending requests to /rest/v1/global_stats using only the public API key.

Affected Systems

Deployments of the Capgo platform that expose the PostgREST /rest/v1/global_stats endpoint and use a public API key are affected. The vulnerability exists in all versions prior to 12.128.2; upgrades to that release or later remove the flaw.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is via the network to the exposed endpoint; attackers can reach it remotely using only the public API key, making exploitation straightforward if the endpoint remains publicly reachable.

Generated by OpenCVE AI on August 1, 2026 at 11:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Capgo 12.128.2 or later, which contains the official fix.
  • If an upgrade is not possible, revoke or disable public API keys that can access the global_stats endpoint, or restrict the endpoint to users with elevated privileges.
  • Apply network‑level controls, such as firewall rules or API gateway restrictions, to limit access to /rest/v1/global_stats to trusted IP addresses or internal networks only.

Generated by OpenCVE AI on August 1, 2026 at 11:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Cap-go
Cap-go cap-go
Vendors & Products Cap-go
Cap-go cap-go

Sun, 12 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote attackers can query the /rest/v1/global_stats endpoint to expose MRR, total revenue, plan-tier revenue breakdown, customer counts, and operational telemetry.
Title Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-13T14:23:57.551Z

Reserved: 2026-06-19T21:50:06.625Z

Link: CVE-2026-56238

cve-icon Vulnrichment

Updated: 2026-07-13T14:23:51.621Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor