


Perceptive Security
SOC/SIEM Consultancy

Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped API key (limited_to_orgs) inherits its ow…
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 16:06:44
Source:
nvd.nist.gov
Identity & Access, Web Technologies, Enterprise Applications
Capgo versions before 12.128.2 contain a broken access control vulnerability in the organization management API. A scoped API key (limited_to_orgs) incorrectly inherits its owner-user's full permissions instead of being restricted to the specified organization. This allows a user who is an admin in multiple organizations to use a write-mode API key restricted to one organization to perform destructive operations against other organizations. Affected endpoints include DELETE /organization and DELETE /organization/members. The root cause lies in route-level authorization (rbac_check_permission_direct) that evaluates the key owner's user privileges before enforcing the API key's limited_to_orgs scope. This privilege inheritance flaw can lead to unauthorized deletion of organizations and their members. Users should upgrade to version 12.128.2 or later to remediate the vulnerability.
Technical details
Mitigation steps:
Affected products:
Capgo
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-56246
https://github.com/Cap-go/capgo/security/advisories/GHSA-ccm4-hf72-p28m
https://www.vulncheck.com/advisories/capgo-cross-organization-authorization-bypass-via-scoped-api-key-privilege-inheritance
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
