PT-2026-51772 · Cap Go · Cap-Go
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
An authorization bypass exists that allows direct patching of the
public.apps.owner org field through PostgREST. This action bypasses the transfer app() workflow, resulting in split-brain ownership. An attacker can update apps.owner org while leaving app versions.owner org unchanged, which allows keys from the previous organization to maintain access to version data while keys from the new organization control the application record.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go