CVE-2026-88861: Authentication Bypass Using an Alternate Path or Channel in Cap-go capgo.app
Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who knows only the victim's password can therefore authenticate, mint a persistent app-scoped app_admin API key that remains valid after the aal1 session is logged out, and perform privileged operations such as modifying production OTA channel configurations (validated by changing a public production channel from bundle 1.0.0 to 1.0.1), defeating the protection provided by MFA.
AI Analysis
Technical Summary
CVE-2026-88861 is an authentication bypass vulnerability in Capgo (capgo.app) affecting all versions. The issue arises because the Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions without validating the MFA assurance level. Specifically, the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts JWT tokens without checking their assurance level, and the RBAC authorization functions (checkPermission()/checkPermissionPg()) authorize by user ID without verifying the session's assurance level, unlike the public.verify_mfa() control which requires aal2. This enables an attacker with only the victim's password to authenticate, mint a persistent app-scoped app_admin API key that remains valid after logout, and perform privileged actions such as modifying production OTA channel configurations, effectively bypassing MFA protections.
Potential Impact
An attacker who knows only the victim's password can bypass MFA protections and gain privileged RBAC permissions. They can mint persistent admin API keys that remain valid beyond the session and perform sensitive operations, including modifying production OTA channel configurations. This compromises the security model that relies on MFA and role-based access control, potentially leading to unauthorized administrative actions and system compromise.
Mitigation Recommendations
No official fix or patch is available at the time of publication. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, users should consider additional compensating controls such as monitoring for unusual API key creation or privileged actions, and restricting access where possible. Avoid relying solely on password authentication and MFA enforcement until the vulnerability is addressed.
CVE-2026-88861: Authentication Bypass Using an Alternate Path or Channel in Cap-go capgo.app
Description
Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who knows only the victim's password can therefore authenticate, mint a persistent app-scoped app_admin API key that remains valid after the aal1 session is logged out, and perform privileged operations such as modifying production OTA channel configurations (validated by changing a public production channel from bundle 1.0.0 to 1.0.1), defeating the protection provided by MFA.
CVSS v4.0
Score 8.7high
Affected software
Cap-go
capgo.app
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-88861 is an authentication bypass vulnerability in Capgo (capgo.app) affecting all versions. The issue arises because the Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions without validating the MFA assurance level. Specifically, the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts JWT tokens without checking their assurance level, and the RBAC authorization functions (checkPermission()/checkPermissionPg()) authorize by user ID without verifying the session's assurance level, unlike the public.verify_mfa() control which requires aal2. This enables an attacker with only the victim's password to authenticate, mint a persistent app-scoped app_admin API key that remains valid after logout, and perform privileged actions such as modifying production OTA channel configurations, effectively bypassing MFA protections.
Potential Impact
An attacker who knows only the victim's password can bypass MFA protections and gain privileged RBAC permissions. They can mint persistent admin API keys that remain valid beyond the session and perform sensitive operations, including modifying production OTA channel configurations. This compromises the security model that relies on MFA and role-based access control, potentially leading to unauthorized administrative actions and system compromise.
Mitigation Recommendations
No official fix or patch is available at the time of publication. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, users should consider additional compensating controls such as monitoring for unusual API key creation or privileged actions, and restricting access where possible. Avoid relying solely on password authentication and MFA enforcement until the vulnerability is addressed.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-10T11:23:56.026Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa2af3dacd9273b4925941a
Added to database: 09/10/2026, 13:23:09 UTC
Last enriched: 09/10/2026, 14:22:16 UTC
Last updated: 09/10/2026, 22:12:33 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.