PT-2026-57548 · Cap Go · Cap-Go
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
An issue exists where users demoted from the
super admin role retain unauthorized access to specific functions. This occurs because the org users.user right column is not cleared during the deletion of role bindings, leading to stale permissions. An attacker can use this to enumerate and bulk delete non-compliant bundles across an entire organization. The affected functions are the delete non compliant bundles and count non compliant bundles RPCs.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
LPE
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go