Junglewise Threat Intelligence

CVE-2026-56216: Capgo scope escalation via API key creation in functions endpoint

CVE-2026-56216 · Severity: high · CVSS 8.8 · Published 2026-06-20

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing mobile app updates, suffered from a security flaw where restricted API keys could be used to create new, unrestricted keys. An attacker with access to a low-privilege key intended for a single application could upgrade their own permissions to gain full access to an entire organization's data and settings. This could lead to unauthorized access to sensitive application listings and other protected administrative functions.

Technical details

A scope escalation vulnerability exists in Capgo's 'POST /functions/v1/apikey' endpoint due to insufficient validation of the caller's existing permissions. The backend logic in 'supabase/functions/_backend/public/apikey/post.ts' only blocked key creation if the caller's key had 'limited_to_orgs' defined, failing to check for 'limited_to_apps' restrictions. A remote attacker with a valid app-limited API key can send a request with empty limit arrays to generate a new key with 'mode: all' and organization-wide access. This allows the attacker to bypass least-privilege controls and access protected endpoints such as '/app' to list all organizational resources. The issue is fixed in version 12.128.2 by ensuring all restricted keys are blocked from minting broader-scope keys.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-03-03: advisory: Initial GitHub security advisory published
  • 2026-06-20: disclosed: CVE published to NVD

References

Related threats