PT-2026-57548 · Cap Go · Cap-Go

·

CVE-2026-56241

·

Published

2026-07-12

·

Updated

2026-07-12

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description An issue exists where users demoted from the super admin role retain unauthorized access to specific functions. This occurs because the org users.user right column is not cleared during the deletion of role bindings, leading to stale permissions. An attacker can use this to enumerate and bulk delete non-compliant bundles across an entire organization. The affected functions are the delete non compliant bundles and count non compliant bundles RPCs.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

LPE

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56241
GHSA-RVVC-RVXV-QCRH

Affected Products

Cap-Go