Skip to main content

CVE-2026-100628: Incorrect Authorization in Cap-go capgo.app

0
High
VulnerabilityCVE-2026-100628cvecve-2026-100628
Published: 09/26/2026 (09/26/2026, 13:23:05 UTC)
Source: CVE Database V5
Vendor/Project: Cap-go
Product: capgo.app

Description

capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST /apikey endpoint, requests that supply app_id but omit org_id, limited_to_orgs, and expires_at resolve the target app and scope the key to it, but never add the app's owner organization to the list of organization IDs passed to validateExpirationAgainstOrgPolicies; because that list is empty, the validation returns early. As a result, an authenticated organization member can create a non-expiring app-scoped API key even when the owning organization has require_apikey_expiration enabled and a max_apikey_expiration_days limit configured. The issue is fixed in version 12.128.12.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

Cap-go

capgo.app

Affected versions
>=0 <12.128.12
GitHub Actionsmore threats →ai
cap-go/capgo.app
pkg:github/cap-go/capgo.app
Affected versions
>=0 <12.128.12

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 14:17:56 UTC

Technical Analysis

CVE-2026-100628 describes an incorrect authorization vulnerability in capgo.app versions prior to 12.128.12. When creating app-scoped API keys via the POST /apikey endpoint, if a request includes app_id but omits org_id, limited_to_orgs, and expires_at, the system scopes the key to the app but does not add the app's owning organization to the list used for validating API key expiration policies. Because this list is empty, the expiration validation is bypassed, allowing an authenticated organization member to create a non-expiring app-scoped API key even if the organization requires API key expiration and enforces a maximum expiration duration. The flaw is fixed in version 12.128.12.

Potential Impact

Authenticated members of an organization can create app-scoped API keys that do not expire, circumventing organizational policies that require API key expiration and limit maximum expiration duration. This could lead to prolonged unauthorized access if such keys are misused or compromised.

Mitigation Recommendations

Upgrade capgo.app to version 12.128.12 or later, where this authorization issue is fixed. No additional mitigation is required once the official fix is applied.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-26T02:31:42.099Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab7c9a3f7a7c5410652fd10

Added to database: 09/26/2026, 13:33:23 UTC

Last enriched: 09/26/2026, 14:17:56 UTC

Last updated: 09/27/2026, 01:57:11 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses