PT-2026-99300 · Cap Go · Cap-Go

·

CVE-2026-100629

·

Published

2026-09-26

·

Updated

2026-10-05

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo (capgo.app backend) versions prior to 12.127.5
Description An authorization flaw exists in the 'PATCH /private/role bindings/:binding id' endpoint. The handler verifies that the priority rank of a newly assigned role does not exceed the caller's rank, but it fails to check the rank of the role currently bound to the target binding. This allows an authenticated user with the org admin role (rank 90) to change an org super admin binding (rank 95) to a lower-privileged role, such as org member (rank 75). Since the prevent last super admin binding delete database trigger only executes before a delete operation and not during an update, an org admin can demote all org super admin users, potentially leaving the organization without a super administrator.
Recommendations Update to version 12.127.5.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100629
GHSA-54MJ-Q77Q-XWX5

Affected Products

Cap-Go