PT-2026-56428 · Cap Go · Cap-Go

·

CVE-2026-56246

·

Published

2026-07-08

·

Updated

2026-07-08

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description Broken access control exists in the organization management API. A scoped API key using the limited to orgs scope inherits the permissions of its owner-user, enabling destructive actions across different organizations. This occurs when a user with administrative privileges in multiple organizations creates a write-mode API key restricted to a single organization; the key can still execute destructive operations against other organizations. The issue stems from the route-level authorization function rbac check permission direct(), which prioritizes the owner's user privileges over the API key's limited to orgs scope. Affected API endpoints include 'DELETE /organization' and 'DELETE /organization/members'.
Recommendations Update to version 12.128.2.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56246
GHSA-CCM4-HF72-P28M

Affected Products

Cap-Go