Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88862— Capgo API Key Manager Authentication Bypass via x-limited-key-id

Quick assessment

Affected
Cap-go capgo.app
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Capgo (capgo.app) 后端在 12.242.4 及更早版本中,在处理 请求头时未正确验证父子委托关系。 中的 函数仅依据密钥 ID、密钥的过期状态以及认证密钥所属用户的 来解析攻击者提供的数字 API 密钥 ID;而 接受任何具有非组织级(例如应用级)RBAC 绑定的密钥, 仅比对密钥所有者的用户 ID。 由于 Capgo 将 API 密钥视为具有独立角色绑定的独立 RBAC 主体,一个已认证的 权限的 API 密钥,即使其本身没有应用访问权限,也可以通过提供同一所有者下权限更高的兄弟密钥的数字 ID

CVSS 8.8 · High

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88862

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Capgo API Key Manager Authentication Bypass via x-limited-key-id
Source: CVE Program / CVE List V5
Vulnerability Description
Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numeric API key ID using only the key ID, its expiration state, and the authenticating key's user_id, while hasLimitedRbacSubkeyScope() accepts any key with a non-organization (e.g., app-scoped) RBAC binding and validateSubkeyUser() only compares owning user IDs. Because Capgo treats API keys as independent RBAC principals with separate role bindings, an authenticated apikey_manager API key with no application access can supply the numeric ID of a more privileged same-owner key and have the middleware replace the authenticated principal and effective API-key secret with that key (setSubkeyAuthContext), exercising an app_admin sibling's permissions without knowing or submitting its secret. The issue was reproduced on release 12.242.4 (commit b3d02cdbc23ac59990785acacd1f113c07458568) after the fix for GHSA-8h52-44r7-w343; at the time of the advisory no patched version was available.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cap-go capgo.app - -

II. Public POCs for CVE-2026-88862

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88862

登录查看更多情报信息。

Vendor Advisories for CVE-2026-88862 (2)

Same Patch Batch · Cap-go · 2026-09-10 · 5 CVEs total

CVE-2026-88864 9.1 CRITICAL Capgo SSO Provider Authentication Bypass via PostgREST Direct Write
CVE-2026-88861 8.3 HIGH Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization
CVE-2026-88863 8.1 HIGH capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org
CVE-2026-88860 6.3 MEDIUM Capgo Authorization Bypass via Stale Channel Permission Overrides

IV. Related Vulnerabilities

V. Comments for CVE-2026-88862

No comments yet


Leave a comment