PT-2026-99286 · Capgo.App · Capgo.App
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
capgo.app versions prior to 12.267.1
Description
Insufficient validation of API key privileges during the rotation process allows a user with the
apikey manager role to rotate a sibling key belonging to a higher-privileged org super admin. By using the PUT endpoint, an attacker can enumerate API keys with the same owner and rotate a more powerful sibling key to recover its plaintext credential, enabling authentication as the higher-privileged principal.Recommendations
Update capgo.app to version 12.267.1 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Capgo.App