Executive brief
Capgo is a mobile application deployment and updates platform. An authentication flaw allows attackers who know only a user's password to bypass enrolled multi-factor authentication (MFA), create persistent API keys, and modify production application configurations even after the initial password session expires. This defeats the intended security protection of MFA and enables long-term unauthorized access to production systems.
Technical details
The vulnerability is an authentication bypass in Capgo's Edge authorization path caused by inconsistent MFA validation. The Edge JWT middleware (foundJWT()) accepts password-only aal1 sessions without validating the assurance level, and the direct RBAC authorization path (checkPermission()/checkPermissionPg()) authorizes users by ID without checking the JWT's aal claim. This differs from Capgo's canonical MFA control (public.verify_mfa()), which correctly requires aal2 for accounts with enrolled MFA factors. An attacker with a victim's password can authenticate with aal1, mint a persistent app-scoped app_admin API key before the session expires, and perform privileged operations such as modifying production OTA channel configurations. The key remains valid even after the aal1 session is logged out. No patch is available as of publication; all versions are affected.
Affected products
- Cap-go Capgo all versions
Timeline
- 2026-09-10: disclosed: Vulnerability disclosed; no patched version available at time of publication