top of page
perceptive_background_267k.jpg

Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped API key (limited_to_orgs) inherits its ow…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 16:06:44

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies, Enterprise Applications

Capgo versions before 12.128.2 contain a broken access control vulnerability in the organization management API. A scoped API key (limited_to_orgs) incorrectly inherits its owner-user's full permissions instead of being restricted to the specified organization. This allows a user who is an admin in multiple organizations to use a write-mode API key restricted to one organization to perform destructive operations against other organizations. Affected endpoints include DELETE /organization and DELETE /organization/members. The root cause lies in route-level authorization (rbac_check_permission_direct) that evaluates the key owner's user privileges before enforcing the API key's limited_to_orgs scope. This privilege inheritance flaw can lead to unauthorized deletion of organizations and their members. Users should upgrade to version 12.128.2 or later to remediate the vulnerability.

Technical details

Mitigation steps:

Affected products:

Capgo

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page