Skip to main content

CVE-2026-100629: Incorrect Authorization in Cap-go capgo.app

0
High
Published: 09/26/2026 (09/26/2026, 15:31:16 UTC)
Source: CVE Database V5
Vendor/Project: Cap-go
Product: capgo.app

Description

Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint. The handler verifies that the newly assigned role's priority rank does not exceed the caller's own rank, but — unlike the DELETE handler — it never checks the rank of the role currently bound to the target binding. An authenticated user holding the org_admin role (rank 90) can therefore change an org_super_admin binding (rank 95) to a lower-privileged role such as org_member (rank 75). Because the prevent_last_super_admin_binding_delete database trigger fires only BEFORE DELETE and not on UPDATE, an org_admin can demote every org_super_admin, leaving the organization with no super administrator. The issue is fixed in 12.127.5.

CVSS v4.0

Score 7.0high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
High
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N

Affected software

Cap-go

capgo.app

Affected versions
>=0 <12.127.5
GitHub Actionsmore threats →ai
cap-go/capgo.app
pkg:github/cap-go/capgo.app
Affected versions
<12.127.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 14:17:52 UTC

Technical Analysis

The vulnerability in capgo.app before version 12.127.5 involves improper authorization checks in the PATCH /private/role_bindings/:binding_id endpoint. While the handler checks that the new role's priority rank does not exceed the caller's rank, it does not verify the rank of the role currently assigned to the binding. Consequently, an org_admin user can demote an org_super_admin binding to a lower-privileged role. The database trigger designed to prevent the last super admin deletion only fires on DELETE operations, not on UPDATE, enabling this demotion. This flaw allows an org_admin to remove all super administrators from an organization, potentially impacting administrative control. The vulnerability is resolved in version 12.127.5.

Potential Impact

An authenticated user with org_admin privileges can demote org_super_admin users to lower roles, effectively removing all super administrators from an organization. This could lead to loss of highest-level administrative control within the organization, potentially disrupting governance and management functions. There are no known exploits in the wild.

Mitigation Recommendations

Upgrade to capgo.app version 12.127.5 or later, where this authorization flaw is fixed. Until then, restrict org_admin privileges carefully and monitor role changes. No other mitigations are specified.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-26T02:31:42.100Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab7c9a3f7a7c5410652fd11

Added to database: 09/26/2026, 13:33:23 UTC

Last enriched: 09/26/2026, 14:17:52 UTC

Last updated: 09/27/2026, 04:31:38 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses