PT-2026-51222 · Cap Go · Cap-Go
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
A broken row level security (RLS) policy in the
org users table allows authenticated users to elevate their privileges from admin to super admin. This insufficient RLS enforcement enables attackers to gain unauthorized super admin access and compromise system security.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
LPE
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go