Executive brief
Capgo is a backend service that manages application deployments and organizational access control. An administrator with standard org_admin privileges can demote any super_admin user to a regular member, and by exploiting a database trigger oversight, can remove all super_admins from an organization. This leaves the organization without any privileged administrators, preventing critical functions like billing management and app deletion.
Technical details
The PATCH /private/role_bindings/:binding_id endpoint validates only that a new role's priority rank does not exceed the caller's rank, but fails to check the existing binding's role rank—a check that the DELETE handler correctly performs. An authenticated org_admin (rank 90) can therefore demote an org_super_admin (rank 95) to org_member (rank 75). Additionally, the prevent_last_super_admin_binding_delete database trigger fires only on DELETE operations, not UPDATE, allowing complete removal of all super_admin bindings via PATCH requests.
Affected products
- Capgo backend before 12.127.5
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: Fixed in version 12.127.5