PT-2026-56425 · Cap Go · Cap-Go

·

CVE-2026-56217

·

Published

2026-07-08

·

Updated

2026-07-08

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description A policy bypass exists in the app versions update enforcement. This issue allows users with app-scoped API keys to downgrade encrypted bundles to a non-encrypted state. An attacker possessing app-scoped all API keys can directly update the app versions table via PostgREST to clear the session key and key id fields. This action bypasses organization-enforced encrypted-bundle policies and weakens Over-the-Air (OTA) security controls.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56217
GHSA-4QWF-MRGX-MVFX

Affected Products

Cap-Go