PT-2026-99300 · Cap Go · Cap-Go
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo (capgo.app backend) versions prior to 12.127.5
Description
An authorization flaw exists in the 'PATCH /private/role bindings/:binding id' endpoint. The handler verifies that the priority rank of a newly assigned role does not exceed the caller's rank, but it fails to check the rank of the role currently bound to the target binding. This allows an authenticated user with the
org admin role (rank 90) to change an org super admin binding (rank 95) to a lower-privileged role, such as org member (rank 75). Since the prevent last super admin binding delete database trigger only executes before a delete operation and not during an update, an org admin can demote all org super admin users, potentially leaving the organization without a super administrator.Recommendations
Update to version 12.127.5.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go