Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100629— Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCH

Quick assessment

Affected
Cap-go capgo.app
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Capgo(capgo.app 后端)在版本 12.127.5 之前存在授权缺陷,影响 端点。该端点处理程序会验证新分配角色的优先级是否不超过调用者自身的角色优先级,但与 处理程序不同,它从未检查当前绑定到目标角色的角色的优先级。因此,持有 角色(优先级 90)的经过身份验证的用户可以将 绑定(优先级 95)降级为权限较低的角色(如 ,优先级 75)。由于防止最后一位超级管理员绑定被删除的数据库触发器仅在 操作前触发,而不会在 操作时触发, 可以将所有 降级,导致组织内没有超级管理员。此问题已在版本 12.127.

CVSS 5.5 · Medium EPSS 0.28% · P18
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100629

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCH
Source: CVE Program / CVE List V5
Vulnerability Description
Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint. The handler verifies that the newly assigned role's priority rank does not exceed the caller's own rank, but — unlike the DELETE handler — it never checks the rank of the role currently bound to the target binding. An authenticated user holding the org_admin role (rank 90) can therefore change an org_super_admin binding (rank 95) to a lower-privileged role such as org_member (rank 75). Because the prevent_last_super_admin_binding_delete database trigger fires only BEFORE DELETE and not on UPDATE, an org_admin can demote every org_super_admin, leaving the organization with no super administrator. The issue is fixed in 12.127.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cap-go capgo.app 0 ~ 12.127.5 -

II. Public POCs for CVE-2026-100629

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100629

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100629 (1)

Other References for CVE-2026-100629 (1)

Same Patch Batch · Cap-go · 2026-09-26 · 19 CVEs total

CVE-2026-100619 8.8 HIGH Capgo OTA Manifest Poisoning via app_versions.manifest Bypass
CVE-2026-100614 8.8 HIGH Capgo before 12.244.1 Cross-Tenant Image Overwrite via Metadata Worker
CVE-2026-100623 8.8 HIGH Capgo Authentication Bypass via Direct PostgREST org_users Table Write
CVE-2026-100617 8.8 HIGH Cap-go capgo.app Authorization Bypass via channel_permission_overrides
CVE-2026-100615 8.8 HIGH Cap-go capgo.app before 12.267.1 Privilege Escalation via API Key Rotation
CVE-2026-100618 8.5 HIGH Capgo App Icon Update Privilege Escalation via Service-Role Worker
CVE-2026-100627 8.1 HIGH Capgo bundle promotion API channel RBAC deny override bypass
CVE-2026-100622 7.5 HIGH capgo.app through 12.129.0 Cache Restoration of Deleted Bundles
CVE-2026-100612 7.2 HIGH Capgo SSO Provider ID Authentication Bypass via Incomplete Migration
CVE-2026-100625 7.1 HIGH Capgo Build Upload Proxy Authorization Bypass via TUS Resource
CVE-2026-100611 6.5 MEDIUM Capgo apikey_manager Role Privilege Escalation via Incomplete Role Deny-list
CVE-2026-100616 5.5 MEDIUM capgo.app Authentication Bypass via PostgREST customer_id Mutation
CVE-2026-100624 5.4 MEDIUM Capgo.app before 12.264.5 Upload Expiry Bypass via build upload
CVE-2026-100613 5.3 MEDIUM capgo.app Authorization Bypass via Stale Channel Permission Overrides
CVE-2026-100626 4.3 MEDIUM capgo through 12.128.2 IDOR via PUT /app icon endpoint
CVE-2026-100628 4.3 MEDIUM capgo.app before 12.128.12 Authentication Bypass via apikey
CVE-2026-100621 4.3 MEDIUM capgo.app Content-Lock Bypass via r2-direct Bundle Mutation
CVE-2026-100620 3.8 LOW Capgo CLI through 7.98.2 Excessive Permissions via Overpermissioned Play Console Service A

IV. Related Vulnerabilities

V. Comments for CVE-2026-100629

No comments yet


Leave a comment