PT-2026-99283 · Cap Go · Cap-Go

·

CVE-2026-100612

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo (capgo.app) versions prior to 12.261.0
Description An incomplete access-control fix in the public.sso providers table allows a user with org admin permissions and the org.update settings permission to perform vertical privilege escalation. While the enforce sso provider client update guard() function restricts updates to certain columns, the provider id, metadata url, and attribute mapping variables remain writable. Due to permissive table grants and row-level security policies that do not restrict specific columns, an attacker can use a PATCH request via PostgREST to change the provider id to an identity provider (IdP) they control. By asserting the organization owner's email through their own IdP, the attacker can merge their identity with the owner's account, resulting in account takeover, password nullification, and lockout of the legitimate owner. This requires the organization to have an active SSO provider configured and the attacker to already possess org admin status.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100612
GHSA-JPJP-V827-J4GC

Affected Products

Cap-Go