PT-2026-51503 · Cap Go · Cap-Go
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
A security control bypass exists in the PostgREST/RLS plane where plaintext API keys are accepted through the
capgkey header, even when enforce hashed api keys is enabled. This allows attackers to bypass organization-level hashed-key enforcement by sending plaintext API keys directly to the PostgREST/RLS plane to access protected resources.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go