CVE-2026-100621: Improper Access Control in Cap-go capgo.app
Capgo (capgo.app) suffers from an incomplete access control vulnerability affecting all versions. The issue allows modification of critical bundle metadata fields when a bundle version is in the 'r2-direct' state, bypassing intended content immutability protections. No patch is currently available.
AI Analysis
Technical Summary
CVE-2026-100621 describes an improper access control flaw in Capgo's capgo.app affecting all versions. The enforcement of content locks in the database schema exempts app_versions rows with a previous storage_provider value of 'r2-direct', leaving key columns mutable. Additionally, the /updates endpoint does not exclude these 'r2-direct' versions, allowing an attacker with a Capgo API key and bundle write/upload permissions to create or maintain a bundle version in this state, assign it to a channel, and modify critical metadata fields such as checksum and session_key via direct PostgREST requests. This effectively bypasses prior post-upload immutability protections.
Potential Impact
An attacker with valid API credentials and bundle upload permissions can alter delivery-critical metadata of app bundles, potentially causing devices to receive manipulated or tampered update information. This undermines the integrity of the update process and could lead to distribution of unauthorized or corrupted content.
Mitigation Recommendations
No patch or official fix is currently available for this vulnerability. Users should monitor vendor advisories for updates. Until a fix is released, restrict API key permissions to the minimum necessary and carefully audit bundle version states, especially those in the 'r2-direct' state, to mitigate risk.
CVE-2026-100621: Improper Access Control in Cap-go capgo.app
Description
Capgo (capgo.app) suffers from an incomplete access control vulnerability affecting all versions. The issue allows modification of critical bundle metadata fields when a bundle version is in the 'r2-direct' state, bypassing intended content immutability protections. No patch is currently available.
CVSS v4.0
Score 5.3medium
Affected software
Cap-go
capgo.app
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100621 describes an improper access control flaw in Capgo's capgo.app affecting all versions. The enforcement of content locks in the database schema exempts app_versions rows with a previous storage_provider value of 'r2-direct', leaving key columns mutable. Additionally, the /updates endpoint does not exclude these 'r2-direct' versions, allowing an attacker with a Capgo API key and bundle write/upload permissions to create or maintain a bundle version in this state, assign it to a channel, and modify critical metadata fields such as checksum and session_key via direct PostgREST requests. This effectively bypasses prior post-upload immutability protections.
Potential Impact
An attacker with valid API credentials and bundle upload permissions can alter delivery-critical metadata of app bundles, potentially causing devices to receive manipulated or tampered update information. This undermines the integrity of the update process and could lead to distribution of unauthorized or corrupted content.
Mitigation Recommendations
No patch or official fix is currently available for this vulnerability. Users should monitor vendor advisories for updates. Until a fix is released, restrict API key permissions to the minimum necessary and carefully audit bundle version states, especially those in the 'r2-direct' state, to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:31:07.602Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a3f7a7c5410652fd09
Added to database: 09/26/2026, 13:33:23 UTC
Last enriched: 09/26/2026, 14:18:27 UTC
Last updated: 09/26/2026, 15:07:46 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.