PT-2026-57427 · Cap Go · Cap-Go
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.12
Description
A billing authorization bypass exists in the
plan valid calculation. This issue allows organizations with expired or exhausted usage credit grants to circumvent billing restrictions due to a divergence between the plugin hot-path plan valid expression and the authoritative billing gate. This can be exploited to maintain unauthorized access to the '/updates', '/stats', '/channel self', and attachment upload endpoints.Recommendations
Update to version 12.128.12 or later.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go