Executive brief
Capgo, a platform for managing app updates and deployments, contained a security flaw that allowed administrators of one organization to gain control over applications belonging to other organizations. By exploiting a weakness in how the system verifies application ownership, an attacker could grant themselves administrative access to a victim's apps. This could lead to unauthorized viewing of sensitive app data or the ability to modify and potentially sabotage another company's applications.
Technical details
An authorization bypass (CWE-639) exists in the `POST /private/role_bindings` endpoint of Capgo due to insufficient validation of application ownership. While the backend verifies that the caller has administrative rights for the `org_id` provided in the request, it fails to verify that the target `app_id` actually belongs to that organization. An attacker with administrative privileges in their own organization can provide a victim's application UUID to create an app-scoped role binding. Because the RBAC engine later resolves permissions based on the actual owner of the application rather than the organization that created the binding, the attacker can grant themselves 'app_admin' privileges over cross-tenant resources. This vulnerability is patched in version 12.128.2.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-05-07: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: NVD publication date