CVE-2026-100611: Improper Privilege Management in Cap-go capgo.app
Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user holding only apikey_manager (permissions org.manage_apikeys and org.read) calls POST /apikey with a JWT session, the only checks applied are the org.manage_apikeys permission, a fixed deny-list of assignable role names (APIKEY_MANAGER_DENIED_ASSIGNABLE_ROLES in public/apikey/scope.ts), and a priority-rank comparison in createRoleBindingForPrincipal (private/role_bindings.ts). No check verifies that the caller actually holds the permissions conferred by the role being assigned. Because the deny-list omits the deploy roles app_developer, app_uploader, channel_developer and channel_uploader, and apikey_manager is seeded with priority_rank 78 — higher than those roles' ranks (68, 66, 58, 57) — the rank check also passes. As a result, an apikey_manager who cannot upload bundles or promote channels can mint an API key bound to a deploy role and use it to push arbitrary OTA JavaScript updates to all end users of the organization's apps. As of the advisory publication no patched version was available.
AI Analysis
Technical Summary
The vulnerability in Capgo's backend (versions ≤ 12.261.0) arises because the apikey_manager role's ability to assign roles to new API keys is insufficiently restricted. The system only enforces a deny-list of roles and a priority-rank check but does not verify that the caller holds the permissions of the assigned role. Since deploy roles like app_developer and app_uploader are omitted from the deny-list and have lower priority ranks than apikey_manager, an attacker with apikey_manager permissions can create API keys with these deploy roles. This allows unauthorized users to push arbitrary OTA JavaScript updates to all end users of the organization's apps.
Potential Impact
An authenticated user with the apikey_manager role can escalate privileges by creating API keys bound to deploy roles that they should not have access to. This enables them to push arbitrary over-the-air JavaScript updates to all users of the organization's applications, potentially leading to unauthorized code execution and compromise of app integrity.
Mitigation Recommendations
As of the advisory publication, no patched version is available. Organizations should monitor vendor advisories for updates. Until a fix is released, restrict apikey_manager role assignments and limit access to users with this role to trusted personnel only.
CVE-2026-100611: Improper Privilege Management in Cap-go capgo.app
Description
Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user holding only apikey_manager (permissions org.manage_apikeys and org.read) calls POST /apikey with a JWT session, the only checks applied are the org.manage_apikeys permission, a fixed deny-list of assignable role names (APIKEY_MANAGER_DENIED_ASSIGNABLE_ROLES in public/apikey/scope.ts), and a priority-rank comparison in createRoleBindingForPrincipal (private/role_bindings.ts). No check verifies that the caller actually holds the permissions conferred by the role being assigned. Because the deny-list omits the deploy roles app_developer, app_uploader, channel_developer and channel_uploader, and apikey_manager is seeded with priority_rank 78 — higher than those roles' ranks (68, 66, 58, 57) — the rank check also passes. As a result, an apikey_manager who cannot upload bundles or promote channels can mint an API key bound to a deploy role and use it to push arbitrary OTA JavaScript updates to all end users of the organization's apps. As of the advisory publication no patched version was available.
CVSS v4.0
Score 7.1high
Affected software
Cap-go
capgo.app
pkg:github/cap-go/capgo.appRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Capgo's backend (versions ≤ 12.261.0) arises because the apikey_manager role's ability to assign roles to new API keys is insufficiently restricted. The system only enforces a deny-list of roles and a priority-rank check but does not verify that the caller holds the permissions of the assigned role. Since deploy roles like app_developer and app_uploader are omitted from the deny-list and have lower priority ranks than apikey_manager, an attacker with apikey_manager permissions can create API keys with these deploy roles. This allows unauthorized users to push arbitrary OTA JavaScript updates to all end users of the organization's apps.
Potential Impact
An authenticated user with the apikey_manager role can escalate privileges by creating API keys bound to deploy roles that they should not have access to. This enables them to push arbitrary over-the-air JavaScript updates to all users of the organization's applications, potentially leading to unauthorized code execution and compromise of app integrity.
Mitigation Recommendations
As of the advisory publication, no patched version is available. Organizations should monitor vendor advisories for updates. Until a fix is released, restrict apikey_manager role assignments and limit access to users with this role to trusted personnel only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:30:34.353Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a1f7a7c5410652fcfc
Added to database: 09/26/2026, 13:33:21 UTC
Last enriched: 09/26/2026, 14:19:06 UTC
Last updated: 09/27/2026, 04:31:35 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.