Skip to main content

CVE-2026-88861: Authentication Bypass Using an Alternate Path or Channel in Cap-go capgo.app

0
High
VulnerabilityCVE-2026-88861cvecve-2026-88861
Published: 09/10/2026 (09/10/2026, 13:05:18 UTC)
Source: CVE Database V5
Vendor/Project: Cap-go
Product: capgo.app

Description

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who knows only the victim's password can therefore authenticate, mint a persistent app-scoped app_admin API key that remains valid after the aal1 session is logged out, and perform privileged operations such as modifying production OTA channel configurations (validated by changing a public production channel from bundle 1.0.0 to 1.0.1), defeating the protection provided by MFA.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected software

Cap-go

capgo.app

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 14:22:16 UTC

Technical Analysis

CVE-2026-88861 is an authentication bypass vulnerability in Capgo (capgo.app) affecting all versions. The issue arises because the Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions without validating the MFA assurance level. Specifically, the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts JWT tokens without checking their assurance level, and the RBAC authorization functions (checkPermission()/checkPermissionPg()) authorize by user ID without verifying the session's assurance level, unlike the public.verify_mfa() control which requires aal2. This enables an attacker with only the victim's password to authenticate, mint a persistent app-scoped app_admin API key that remains valid after logout, and perform privileged actions such as modifying production OTA channel configurations, effectively bypassing MFA protections.

Potential Impact

An attacker who knows only the victim's password can bypass MFA protections and gain privileged RBAC permissions. They can mint persistent admin API keys that remain valid beyond the session and perform sensitive operations, including modifying production OTA channel configurations. This compromises the security model that relies on MFA and role-based access control, potentially leading to unauthorized administrative actions and system compromise.

Mitigation Recommendations

No official fix or patch is available at the time of publication. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, users should consider additional compensating controls such as monitoring for unusual API key creation or privileged actions, and restricting access where possible. Avoid relying solely on password authentication and MFA enforcement until the vulnerability is addressed.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-10T11:23:56.026Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6aa2af3dacd9273b4925941a

Added to database: 09/10/2026, 13:23:09 UTC

Last enriched: 09/10/2026, 14:22:16 UTC

Last updated: 09/10/2026, 22:12:33 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses