PT-2026-99299 · Capgo.App · Capgo.App

·

CVE-2026-100628

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions capgo.app versions prior to 12.128.12
Description An authenticated organization member can create a non-expiring app-scoped API key, bypassing the organization's API key expiration policy. This occurs when the owning organization has require apikey expiration enabled and a max apikey expiration days limit configured. In the 'POST /apikey' endpoint, requests that provide app id but omit org id, limited to orgs, and expires at fail to add the app's owner organization to the list of IDs passed to the validateExpirationAgainstOrgPolicies() function. Because the list is empty, the validation process returns early without enforcing the expiration policy.
Recommendations Update to version 12.128.12.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100628
GHSA-J6P6-QQCG-3FWP

Affected Products

Capgo.App