Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100627— Capgo bundle promotion API channel RBAC deny override bypass

Quick assessment

Affected
Cap-go capgo.app
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Capgo (Cap-go/capgo.app) 后端服务中使用的 Supabase 函数在 API 密钥绑定的推广路径中存在授权逻辑缺陷。 端点接受拥有 “all” 或 “write” 权限的 API 密钥,并调用 函数进行处理。该函数通过 进行权限验证,但遗漏了请求中的 字段。 由于被遗漏的作用域字段作为 SQL 传递给了 函数,而基于 的作用域覆盖评估逻辑受限于 条件,因此针对特定通道的允许/拒绝覆盖规则永远不会被评估。 因此,任何拥有应用级 权限的主体(该权限默认授予 和 角色),都可以将某个代码包(bun

CVSS 8.1 · High EPSS 0.29% · P20
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100627

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Capgo bundle promotion API channel RBAC deny override bypass
Source: CVE Program / CVE List V5
Vulnerability Description
Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API keys, dispatches to setChannel, which authorizes with checkPermission(c, 'channel.promote_bundle', { appId: body.app_id }) and omits the request's channel_id. Because the omitted scope field is passed to rbac_check_permission_direct as SQL NULL, and channel-scope override evaluation is gated on p_channel_id IS NOT NULL, per-channel allow/deny overrides are never evaluated. A principal holding app-level channel.promote_bundle (granted by default to the app_developer and app_uploader roles) can therefore promote a bundle to a channel for which an explicit per-channel deny override exists, updating public.channels.version for the supplied channel_id; the target channel is only validated after authorization. The issue is confirmed on main at commit de66fa51e7ff2f50283cc1455c3d80ab3eb0ae43 and likely earlier versions; no patched version is known at the time of publication.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cap-go capgo.app - -

II. Public POCs for CVE-2026-100627

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100627

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100627 (1)

Other References for CVE-2026-100627 (1)

Same Patch Batch · Cap-go · 2026-09-26 · 19 CVEs total

CVE-2026-100619 8.8 HIGH Capgo OTA Manifest Poisoning via app_versions.manifest Bypass
CVE-2026-100614 8.8 HIGH Capgo before 12.244.1 Cross-Tenant Image Overwrite via Metadata Worker
CVE-2026-100623 8.8 HIGH Capgo Authentication Bypass via Direct PostgREST org_users Table Write
CVE-2026-100617 8.8 HIGH Cap-go capgo.app Authorization Bypass via channel_permission_overrides
CVE-2026-100615 8.8 HIGH Cap-go capgo.app before 12.267.1 Privilege Escalation via API Key Rotation
CVE-2026-100618 8.5 HIGH Capgo App Icon Update Privilege Escalation via Service-Role Worker
CVE-2026-100622 7.5 HIGH capgo.app through 12.129.0 Cache Restoration of Deleted Bundles
CVE-2026-100612 7.2 HIGH Capgo SSO Provider ID Authentication Bypass via Incomplete Migration
CVE-2026-100625 7.1 HIGH Capgo Build Upload Proxy Authorization Bypass via TUS Resource
CVE-2026-100611 6.5 MEDIUM Capgo apikey_manager Role Privilege Escalation via Incomplete Role Deny-list
CVE-2026-100629 5.5 MEDIUM Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCH
CVE-2026-100616 5.5 MEDIUM capgo.app Authentication Bypass via PostgREST customer_id Mutation
CVE-2026-100624 5.4 MEDIUM Capgo.app before 12.264.5 Upload Expiry Bypass via build upload
CVE-2026-100613 5.3 MEDIUM capgo.app Authorization Bypass via Stale Channel Permission Overrides
CVE-2026-100626 4.3 MEDIUM capgo through 12.128.2 IDOR via PUT /app icon endpoint
CVE-2026-100628 4.3 MEDIUM capgo.app before 12.128.12 Authentication Bypass via apikey
CVE-2026-100621 4.3 MEDIUM capgo.app Content-Lock Bypass via r2-direct Bundle Mutation
CVE-2026-100620 3.8 LOW Capgo CLI through 7.98.2 Excessive Permissions via Overpermissioned Play Console Service A

IV. Related Vulnerabilities

V. Comments for CVE-2026-100627

No comments yet


Leave a comment