CVE-2026-88862: Incorrect Authorization in Cap-go capgo.app
Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numeric API key ID using only the key ID, its expiration state, and the authenticating key's user_id, while hasLimitedRbacSubkeyScope() accepts any key with a non-organization (e.g., app-scoped) RBAC binding and validateSubkeyUser() only compares owning user IDs. Because Capgo treats API keys as independent RBAC principals with separate role bindings, an authenticated apikey_manager API key with no application access can supply the numeric ID of a more privileged same-owner key and have the middleware replace the authenticated principal and effective API-key secret with that key (setSubkeyAuthContext), exercising an app_admin sibling's permissions without knowing or submitting its secret. The issue was reproduced on release 12.242.4 (commit b3d02cdbc23ac59990785acacd1f113c07458568) after the fix for GHSA-8h52-44r7-w343; at the time of the advisory no patched version was available.
AI Analysis
Technical Summary
Capgo's backend through version 12.242.4 fails to correctly validate delegation relationships between API keys when handling the x-limited-key-id header. The function checkKeyByIdPg() resolves API keys based on key ID, expiration, and user ID but does not verify proper delegation. Because API keys are treated as independent RBAC principals, an attacker with an authenticated apikey_manager key lacking application access can supply the numeric ID of a sibling key with higher privileges owned by the same user. The middleware then replaces the authenticated principal and API key secret with those of the privileged key, effectively granting the attacker elevated permissions without needing the privileged key's secret. This vulnerability was confirmed on release 12.242.4, and no fix was available at the time of publication.
Potential Impact
An attacker with an authenticated API key that has limited privileges can escalate their permissions to those of a more privileged key owned by the same user. This unauthorized privilege escalation can lead to unauthorized access and control over application resources that should be restricted, potentially compromising the security and integrity of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict issuance and use of API keys with elevated privileges and monitor for suspicious use of API keys. Avoid relying on the x-limited-key-id header for authorization decisions if possible.
CVE-2026-88862: Incorrect Authorization in Cap-go capgo.app
Description
Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numeric API key ID using only the key ID, its expiration state, and the authenticating key's user_id, while hasLimitedRbacSubkeyScope() accepts any key with a non-organization (e.g., app-scoped) RBAC binding and validateSubkeyUser() only compares owning user IDs. Because Capgo treats API keys as independent RBAC principals with separate role bindings, an authenticated apikey_manager API key with no application access can supply the numeric ID of a more privileged same-owner key and have the middleware replace the authenticated principal and effective API-key secret with that key (setSubkeyAuthContext), exercising an app_admin sibling's permissions without knowing or submitting its secret. The issue was reproduced on release 12.242.4 (commit b3d02cdbc23ac59990785acacd1f113c07458568) after the fix for GHSA-8h52-44r7-w343; at the time of the advisory no patched version was available.
CVSS v4.0
Score 8.7high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Capgo's backend through version 12.242.4 fails to correctly validate delegation relationships between API keys when handling the x-limited-key-id header. The function checkKeyByIdPg() resolves API keys based on key ID, expiration, and user ID but does not verify proper delegation. Because API keys are treated as independent RBAC principals, an attacker with an authenticated apikey_manager key lacking application access can supply the numeric ID of a sibling key with higher privileges owned by the same user. The middleware then replaces the authenticated principal and API key secret with those of the privileged key, effectively granting the attacker elevated permissions without needing the privileged key's secret. This vulnerability was confirmed on release 12.242.4, and no fix was available at the time of publication.
Potential Impact
An attacker with an authenticated API key that has limited privileges can escalate their permissions to those of a more privileged key owned by the same user. This unauthorized privilege escalation can lead to unauthorized access and control over application resources that should be restricted, potentially compromising the security and integrity of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict issuance and use of API keys with elevated privileges and monitor for suspicious use of API keys. Avoid relying on the x-limited-key-id header for authorization decisions if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-10T11:23:56.027Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa2af3dacd9273b4925941c
Added to database: 09/10/2026, 13:23:09 UTC
Last enriched: 09/10/2026, 14:22:11 UTC
Last updated: 09/10/2026, 16:52:28 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.