Skip to main content
Reconnecting to live updates…

CVE-2026-88862: Incorrect Authorization in Cap-go capgo.app

0
High
VulnerabilityCVE-2026-88862cvecve-2026-88862
Published: 09/10/2026 (09/10/2026, 13:05:19 UTC)
Source: CVE Database V5
Vendor/Project: Cap-go
Product: capgo.app

Description

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numeric API key ID using only the key ID, its expiration state, and the authenticating key's user_id, while hasLimitedRbacSubkeyScope() accepts any key with a non-organization (e.g., app-scoped) RBAC binding and validateSubkeyUser() only compares owning user IDs. Because Capgo treats API keys as independent RBAC principals with separate role bindings, an authenticated apikey_manager API key with no application access can supply the numeric ID of a more privileged same-owner key and have the middleware replace the authenticated principal and effective API-key secret with that key (setSubkeyAuthContext), exercising an app_admin sibling's permissions without knowing or submitting its secret. The issue was reproduced on release 12.242.4 (commit b3d02cdbc23ac59990785acacd1f113c07458568) after the fix for GHSA-8h52-44r7-w343; at the time of the advisory no patched version was available.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 14:22:11 UTC

Technical Analysis

Capgo's backend through version 12.242.4 fails to correctly validate delegation relationships between API keys when handling the x-limited-key-id header. The function checkKeyByIdPg() resolves API keys based on key ID, expiration, and user ID but does not verify proper delegation. Because API keys are treated as independent RBAC principals, an attacker with an authenticated apikey_manager key lacking application access can supply the numeric ID of a sibling key with higher privileges owned by the same user. The middleware then replaces the authenticated principal and API key secret with those of the privileged key, effectively granting the attacker elevated permissions without needing the privileged key's secret. This vulnerability was confirmed on release 12.242.4, and no fix was available at the time of publication.

Potential Impact

An attacker with an authenticated API key that has limited privileges can escalate their permissions to those of a more privileged key owned by the same user. This unauthorized privilege escalation can lead to unauthorized access and control over application resources that should be restricted, potentially compromising the security and integrity of the affected system.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict issuance and use of API keys with elevated privileges and monitor for suspicious use of API keys. Avoid relying on the x-limited-key-id header for authorization decisions if possible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-10T11:23:56.027Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6aa2af3dacd9273b4925941c

Added to database: 09/10/2026, 13:23:09 UTC

Last enriched: 09/10/2026, 14:22:11 UTC

Last updated: 09/10/2026, 16:52:28 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses