Skip to main content

CVE-2026-100620: Improper Privilege Management in Cap-go @capgo/cli

0
Medium
Published: 09/26/2026 (09/26/2026, 15:31:15 UTC)
Source: CVE Database V5
Vendor/Project: Cap-go
Product: @capgo/cli

Description

Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL (passed as developerAccountPermissions in the Android Publisher API User create request), even though the user-facing flow states the service account is invited into a single confirmed app with release-only permissions. As a result, anyone who obtains the generated service account key (PLAY_CONFIG_JSON) can create, edit, and delete draft apps across the entire Google Play developer account rather than being limited to the selected package. No patched version was available at the time of publication.

CVSS v4.0

Score 5.1medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
High
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected software

Cap-go

@capgo/cli

Affected versions
>=0 <=7.98.2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 14:18:32 UTC

Technical Analysis

The Capgo CLI (@capgo/cli) versions up to 7.98.2 improperly assign excessive permissions to a Google Play service account generated during the Android onboarding process. Specifically, the service account is granted the CAN_MANAGE_DRAFT_APPS_GLOBAL permission, which applies account-wide, rather than restricting permissions to a single app with release-only capabilities as indicated by the user-facing flow. This discrepancy creates a privilege management flaw where possession of the service account key enables creation, modification, and deletion of draft apps across the entire Google Play developer account.

Potential Impact

An attacker who obtains the service account key (PLAY_CONFIG_JSON) can exercise broad control over all draft apps in the Google Play developer account, including creating, editing, and deleting draft apps. This exceeds the intended scope of permissions and could lead to unauthorized app modifications or disruptions across the entire developer account.

Mitigation Recommendations

No official patch or fix was available at the time of publication. Users should exercise caution with the service account keys generated by the Capgo CLI and restrict access to them. Monitor for updates from the vendor for an official fix and apply it once available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-26T02:31:07.602Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab7c9a3f7a7c5410652fd08

Added to database: 09/26/2026, 13:33:23 UTC

Last enriched: 09/26/2026, 14:18:32 UTC

Last updated: 09/27/2026, 04:31:38 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses