Capgo.App · Capgo.App · CVE-2026-100615
**Name of the Vulnerable Software and Affected Versions**
capgo.app versions prior to 12.267.1
**Description**
Insufficient validation of API key privileges during the rotation process allows a user with the `apikey manager` role to rotate a sibling key belonging to a higher-privileged `org super admin`. By using the PUT endpoint, an attacker can enumerate API keys with the same owner and rotate a more powerful sibling key to recover its plaintext credential, enabling authentication as the higher-privileged principal.
**Recommendations**
Update capgo.app to version 12.267.1 or later.