Capgo (capgo.app) 后端在 12.242.4 及更早版本中,在处理 请求头时未正确验证父子委托关系。 中的 函数仅依据密钥 ID、密钥的过期状态以及认证密钥所属用户的 来解析攻击者提供的数字 API 密钥 ID;而 接受任何具有非组织级(例如应用级)RBAC 绑定的密钥, 仅比对密钥所有者的用户 ID。 由于 Capgo 将 API 密钥视为具有独立角色绑定的独立 RBAC 主体,一个已认证的 权限的 API 密钥,即使其本身没有应用访问权限,也可以通过提供同一所有者下权限更高的兄弟密钥的数字 ID
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88864 | 9.1 CRITICAL | Capgo SSO Provider Authentication Bypass via PostgREST Direct Write |
| CVE-2026-88861 | 8.3 HIGH | Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization |
| CVE-2026-88863 | 8.1 HIGH | capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org |
| CVE-2026-88860 | 6.3 MEDIUM | Capgo Authorization Bypass via Stale Channel Permission Overrides |
No comments yet