当用户最后一个组织角色绑定被删除时,Capgo 未能清理通道权限覆盖项,导致过期的覆盖项仍处于激活状态。攻击者在基础 RBAC 访问权限被撤销后,仍可保留特定通道的权限,从而执行未经授权的操作,例如更改生产环境的 OTA 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88864 | 9.1 CRITICAL | Capgo SSO Provider Authentication Bypass via PostgREST Direct Write |
| CVE-2026-88862 | 8.8 HIGH | Capgo API Key Manager Authentication Bypass via x-limited-key-id |
| CVE-2026-88861 | 8.3 HIGH | Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization |
| CVE-2026-88863 | 8.1 HIGH | capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org |
No comments yet