PT-2026-99282 · Cap Go · Cap-Go

·

CVE-2026-100611

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.261.1
Description The backend improperly restricts the roles that the apikey manager organization role can assign to new API keys. When an authenticated user with apikey manager permissions (specifically org.manage apikeys and org.read) calls the 'POST /apikey' endpoint, the system fails to verify if the caller possesses the permissions of the role being assigned. The validation process relies on a deny-list and a priority-rank comparison in the createRoleBindingForPrincipal() function. Since the deny-list omits several deploy roles—app developer, app uploader, channel developer, and channel uploader—and the apikey manager has a higher priority rank than these roles, the check is bypassed. This allows a user with limited privileges to create an API key with deploy roles and push arbitrary Over-the-Air (OTA) JavaScript updates to all end users of the organization's applications.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100611

Affected Products

Cap-Go