Skip to main content

CVE-2026-100611: Improper Privilege Management in Cap-go capgo.app

0
High
Published: 09/26/2026 (09/26/2026, 15:31:14 UTC)
Source: CVE Database V5
Vendor/Project: Cap-go
Product: capgo.app

Description

Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user holding only apikey_manager (permissions org.manage_apikeys and org.read) calls POST /apikey with a JWT session, the only checks applied are the org.manage_apikeys permission, a fixed deny-list of assignable role names (APIKEY_MANAGER_DENIED_ASSIGNABLE_ROLES in public/apikey/scope.ts), and a priority-rank comparison in createRoleBindingForPrincipal (private/role_bindings.ts). No check verifies that the caller actually holds the permissions conferred by the role being assigned. Because the deny-list omits the deploy roles app_developer, app_uploader, channel_developer and channel_uploader, and apikey_manager is seeded with priority_rank 78 — higher than those roles' ranks (68, 66, 58, 57) — the rank check also passes. As a result, an apikey_manager who cannot upload bundles or promote channels can mint an API key bound to a deploy role and use it to push arbitrary OTA JavaScript updates to all end users of the organization's apps. As of the advisory publication no patched version was available.

CVSS v4.0

Score 7.1high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Affected software

Cap-go

capgo.app

GitHub Actionsmore threats →ai
cap-go/capgo.app
pkg:github/cap-go/capgo.app
Affected versions
<=12.261.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 14:19:06 UTC

Technical Analysis

The vulnerability in Capgo's backend (versions ≤ 12.261.0) arises because the apikey_manager role's ability to assign roles to new API keys is insufficiently restricted. The system only enforces a deny-list of roles and a priority-rank check but does not verify that the caller holds the permissions of the assigned role. Since deploy roles like app_developer and app_uploader are omitted from the deny-list and have lower priority ranks than apikey_manager, an attacker with apikey_manager permissions can create API keys with these deploy roles. This allows unauthorized users to push arbitrary OTA JavaScript updates to all end users of the organization's apps.

Potential Impact

An authenticated user with the apikey_manager role can escalate privileges by creating API keys bound to deploy roles that they should not have access to. This enables them to push arbitrary over-the-air JavaScript updates to all users of the organization's applications, potentially leading to unauthorized code execution and compromise of app integrity.

Mitigation Recommendations

As of the advisory publication, no patched version is available. Organizations should monitor vendor advisories for updates. Until a fix is released, restrict apikey_manager role assignments and limit access to users with this role to trusted personnel only.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-26T02:30:34.353Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab7c9a1f7a7c5410652fcfc

Added to database: 09/26/2026, 13:33:21 UTC

Last enriched: 09/26/2026, 14:19:06 UTC

Last updated: 09/27/2026, 04:31:35 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses