Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Dcr6174

#16636of 57,348
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2026-99285
8.8
2026-09-26
Cap Go · Cap-Go · CVE-2026-100614
**Name of the Vulnerable Software and Affected Versions** Capgo versions prior to 12.244.1 **Description** A cross-tenant integrity issue exists in the metadata-cleaning worker. The worker trusts image object keys from mutable database rows without validating ownership, acting as a confused deputy. An authenticated attacker can insert a victim tenant's image key into a row they control. This triggers the service-role worker to download and re-upload the object with sanitized metadata, allowing the attacker to silently modify metadata in cross-tenant image objects and bypass storage access controls during authorized row updates. **Recommendations** Update Capgo to version 12.244.1 or later.
PT-2026-99286
8.8
2026-09-26
Capgo.App · Capgo.App · CVE-2026-100615
**Name of the Vulnerable Software and Affected Versions** capgo.app versions prior to 12.267.1 **Description** Insufficient validation of API key privileges during the rotation process allows a user with the `apikey manager` role to rotate a sibling key belonging to a higher-privileged `org super admin`. By using the PUT endpoint, an attacker can enumerate API keys with the same owner and rotate a more powerful sibling key to recover its plaintext credential, enabling authentication as the higher-privileged principal. **Recommendations** Update capgo.app to version 12.267.1 or later.