PT-2026-57174 · Cap Go · Cap-Go
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
An authorization bypass exists where write-scoped API keys can directly mutate protected channel configuration fields via PostgREST. This occurs due to a null authentication check in the immutability trigger, allowing attackers with write API keys to modify sensitive channel attributes such as
public, allow emulator, and security-related flags outside of the intended application routes.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go