PT-2026-99299 · Capgo.App · Capgo.App
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
capgo.app versions prior to 12.128.12
Description
An authenticated organization member can create a non-expiring app-scoped API key, bypassing the organization's API key expiration policy. This occurs when the owning organization has
require apikey expiration enabled and a max apikey expiration days limit configured. In the 'POST /apikey' endpoint, requests that provide app id but omit org id, limited to orgs, and expires at fail to add the app's owner organization to the list of IDs passed to the validateExpirationAgainstOrgPolicies() function. Because the list is empty, the validation process returns early without enforcing the expiration policy.Recommendations
Update to version 12.128.12.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Capgo.App