PT-2026-99282 · Cap Go · Cap-Go
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.261.1
Description
The backend improperly restricts the roles that the
apikey manager organization role can assign to new API keys. When an authenticated user with apikey manager permissions (specifically org.manage apikeys and org.read) calls the 'POST /apikey' endpoint, the system fails to verify if the caller possesses the permissions of the role being assigned. The validation process relies on a deny-list and a priority-rank comparison in the createRoleBindingForPrincipal() function. Since the deny-list omits several deploy roles—app developer, app uploader, channel developer, and channel uploader—and the apikey manager has a higher priority rank than these roles, the check is bypassed. This allows a user with limited privileges to create an API key with deploy roles and push arbitrary Over-the-Air (OTA) JavaScript updates to all end users of the organization's applications.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go