Junglewise Threat Intelligence

CVE-2026-56225: Capgo authorization bypass in API key management handlers

CVE-2026-56225 · Severity: high · CVSS 8.3 · Published 2026-06-23

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and deployments, contained a security flaw in how it handles API keys. An attacker with a restricted API key (limited to a specific app) could bypass security boundaries to view, modify, or delete other API keys belonging to the same account. This could lead to unauthorized access to other applications or a complete takeover of the account's management credentials.

Technical details

An authorization bypass exists in Capgo's public API key management handlers (GET, PUT, POST, DELETE) due to improper scope validation. While the system checks for organization-level restrictions (limited_to_orgs), it fails to enforce app-level restrictions (limited_to_apps) for keys created with 'mode=all'. A remote attacker with low privileges (possessing an app-scoped API key) can enumerate, update, or delete sibling API keys belonging to the same account but associated with different applications. This allows for privilege escalation and tampering with account-level credentials. The issue is resolved in version 12.128.2.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-05-07: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: NVD publication date

References

Related threats