CVE-2026-100628: Incorrect Authorization in Cap-go capgo.app
capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST /apikey endpoint, requests that supply app_id but omit org_id, limited_to_orgs, and expires_at resolve the target app and scope the key to it, but never add the app's owner organization to the list of organization IDs passed to validateExpirationAgainstOrgPolicies; because that list is empty, the validation returns early. As a result, an authenticated organization member can create a non-expiring app-scoped API key even when the owning organization has require_apikey_expiration enabled and a max_apikey_expiration_days limit configured. The issue is fixed in version 12.128.12.
AI Analysis
Technical Summary
CVE-2026-100628 describes an incorrect authorization vulnerability in capgo.app versions prior to 12.128.12. When creating app-scoped API keys via the POST /apikey endpoint, if a request includes app_id but omits org_id, limited_to_orgs, and expires_at, the system scopes the key to the app but does not add the app's owning organization to the list used for validating API key expiration policies. Because this list is empty, the expiration validation is bypassed, allowing an authenticated organization member to create a non-expiring app-scoped API key even if the organization requires API key expiration and enforces a maximum expiration duration. The flaw is fixed in version 12.128.12.
Potential Impact
Authenticated members of an organization can create app-scoped API keys that do not expire, circumventing organizational policies that require API key expiration and limit maximum expiration duration. This could lead to prolonged unauthorized access if such keys are misused or compromised.
Mitigation Recommendations
Upgrade capgo.app to version 12.128.12 or later, where this authorization issue is fixed. No additional mitigation is required once the official fix is applied.
CVE-2026-100628: Incorrect Authorization in Cap-go capgo.app
Description
capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST /apikey endpoint, requests that supply app_id but omit org_id, limited_to_orgs, and expires_at resolve the target app and scope the key to it, but never add the app's owner organization to the list of organization IDs passed to validateExpirationAgainstOrgPolicies; because that list is empty, the validation returns early. As a result, an authenticated organization member can create a non-expiring app-scoped API key even when the owning organization has require_apikey_expiration enabled and a max_apikey_expiration_days limit configured. The issue is fixed in version 12.128.12.
CVSS v4.0
Score 8.7high
Affected software
Cap-go
capgo.app
pkg:github/cap-go/capgo.appRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100628 describes an incorrect authorization vulnerability in capgo.app versions prior to 12.128.12. When creating app-scoped API keys via the POST /apikey endpoint, if a request includes app_id but omits org_id, limited_to_orgs, and expires_at, the system scopes the key to the app but does not add the app's owning organization to the list used for validating API key expiration policies. Because this list is empty, the expiration validation is bypassed, allowing an authenticated organization member to create a non-expiring app-scoped API key even if the organization requires API key expiration and enforces a maximum expiration duration. The flaw is fixed in version 12.128.12.
Potential Impact
Authenticated members of an organization can create app-scoped API keys that do not expire, circumventing organizational policies that require API key expiration and limit maximum expiration duration. This could lead to prolonged unauthorized access if such keys are misused or compromised.
Mitigation Recommendations
Upgrade capgo.app to version 12.128.12 or later, where this authorization issue is fixed. No additional mitigation is required once the official fix is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:31:42.099Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a3f7a7c5410652fd10
Added to database: 09/26/2026, 13:33:23 UTC
Last enriched: 09/26/2026, 14:17:56 UTC
Last updated: 09/27/2026, 01:57:11 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.