CVE-2026-100620: Improper Privilege Management in Cap-go @capgo/cli
Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL (passed as developerAccountPermissions in the Android Publisher API User create request), even though the user-facing flow states the service account is invited into a single confirmed app with release-only permissions. As a result, anyone who obtains the generated service account key (PLAY_CONFIG_JSON) can create, edit, and delete draft apps across the entire Google Play developer account rather than being limited to the selected package. No patched version was available at the time of publication.
AI Analysis
Technical Summary
The Capgo CLI (@capgo/cli) versions up to 7.98.2 improperly assign excessive permissions to a Google Play service account generated during the Android onboarding process. Specifically, the service account is granted the CAN_MANAGE_DRAFT_APPS_GLOBAL permission, which applies account-wide, rather than restricting permissions to a single app with release-only capabilities as indicated by the user-facing flow. This discrepancy creates a privilege management flaw where possession of the service account key enables creation, modification, and deletion of draft apps across the entire Google Play developer account.
Potential Impact
An attacker who obtains the service account key (PLAY_CONFIG_JSON) can exercise broad control over all draft apps in the Google Play developer account, including creating, editing, and deleting draft apps. This exceeds the intended scope of permissions and could lead to unauthorized app modifications or disruptions across the entire developer account.
Mitigation Recommendations
No official patch or fix was available at the time of publication. Users should exercise caution with the service account keys generated by the Capgo CLI and restrict access to them. Monitor for updates from the vendor for an official fix and apply it once available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-100620: Improper Privilege Management in Cap-go @capgo/cli
Description
Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL (passed as developerAccountPermissions in the Android Publisher API User create request), even though the user-facing flow states the service account is invited into a single confirmed app with release-only permissions. As a result, anyone who obtains the generated service account key (PLAY_CONFIG_JSON) can create, edit, and delete draft apps across the entire Google Play developer account rather than being limited to the selected package. No patched version was available at the time of publication.
CVSS v4.0
Score 5.1medium
Affected software
Cap-go
@capgo/cli
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Capgo CLI (@capgo/cli) versions up to 7.98.2 improperly assign excessive permissions to a Google Play service account generated during the Android onboarding process. Specifically, the service account is granted the CAN_MANAGE_DRAFT_APPS_GLOBAL permission, which applies account-wide, rather than restricting permissions to a single app with release-only capabilities as indicated by the user-facing flow. This discrepancy creates a privilege management flaw where possession of the service account key enables creation, modification, and deletion of draft apps across the entire Google Play developer account.
Potential Impact
An attacker who obtains the service account key (PLAY_CONFIG_JSON) can exercise broad control over all draft apps in the Google Play developer account, including creating, editing, and deleting draft apps. This exceeds the intended scope of permissions and could lead to unauthorized app modifications or disruptions across the entire developer account.
Mitigation Recommendations
No official patch or fix was available at the time of publication. Users should exercise caution with the service account keys generated by the Capgo CLI and restrict access to them. Monitor for updates from the vendor for an official fix and apply it once available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:31:07.602Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a3f7a7c5410652fd08
Added to database: 09/26/2026, 13:33:23 UTC
Last enriched: 09/26/2026, 14:18:32 UTC
Last updated: 09/27/2026, 04:31:38 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.