Junglewise Threat Intelligence

CVE-2026-100629: Capgo backend authorization flaw in role bindings PATCH endpoint

CVE-2026-100629 · Severity: medium · CVSS 5.5 · Published 2026-09-26

Vendors: Capgo.

Executive brief

Capgo is a backend service that manages application deployments and organizational access control. An administrator with standard org_admin privileges can demote any super_admin user to a regular member, and by exploiting a database trigger oversight, can remove all super_admins from an organization. This leaves the organization without any privileged administrators, preventing critical functions like billing management and app deletion.

Technical details

The PATCH /private/role_bindings/:binding_id endpoint validates only that a new role's priority rank does not exceed the caller's rank, but fails to check the existing binding's role rank—a check that the DELETE handler correctly performs. An authenticated org_admin (rank 90) can therefore demote an org_super_admin (rank 95) to org_member (rank 75). Additionally, the prevent_last_super_admin_binding_delete database trigger fires only on DELETE operations, not UPDATE, allowing complete removal of all super_admin bindings via PATCH requests.

Affected products

  • Capgo backend before 12.127.5

Timeline

  • 2026-09-26: disclosed
  • 2026-09-26: patched: Fixed in version 12.127.5

References