PT-2026-99286 · Capgo.App · Capgo.App

·

CVE-2026-100615

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions capgo.app versions prior to 12.267.1
Description Insufficient validation of API key privileges during the rotation process allows a user with the apikey manager role to rotate a sibling key belonging to a higher-privileged org super admin. By using the PUT endpoint, an attacker can enumerate API keys with the same owner and rotate a more powerful sibling key to recover its plaintext credential, enabling authentication as the higher-privileged principal.
Recommendations Update capgo.app to version 12.267.1 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100615
GHSA-8H52-44R7-W343

Affected Products

Capgo.App