PT-2026-99285 · Cap Go · Cap-Go

·

CVE-2026-100614

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.244.1
Description A cross-tenant integrity issue exists in the metadata-cleaning worker. The worker trusts image object keys from mutable database rows without validating ownership, acting as a confused deputy. An authenticated attacker can insert a victim tenant's image key into a row they control. This triggers the service-role worker to download and re-upload the object with sanitized metadata, allowing the attacker to silently modify metadata in cross-tenant image objects and bypass storage access controls during authorized row updates.
Recommendations Update Capgo to version 12.244.1 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100614
GHSA-RCRW-PG2V-J9XG

Affected Products

Cap-Go