PT-2026-99283 · Cap Go · Cap-Go
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo (capgo.app) versions prior to 12.261.0
Description
An incomplete access-control fix in the
public.sso providers table allows a user with org admin permissions and the org.update settings permission to perform vertical privilege escalation. While the enforce sso provider client update guard() function restricts updates to certain columns, the provider id, metadata url, and attribute mapping variables remain writable. Due to permissive table grants and row-level security policies that do not restrict specific columns, an attacker can use a PATCH request via PostgREST to change the provider id to an identity provider (IdP) they control. By asserting the organization owner's email through their own IdP, the attacker can merge their identity with the owner's account, resulting in account takeover, password nullification, and lockout of the legitimate owner. This requires the organization to have an active SSO provider configured and the attacker to already possess org admin status.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go