Impact
The vulnerability is a failure to validate the privilege level of a target API key during rotation. An account that holds the apikey_manager role can rotate a sibling key that has higher privileges, recover the plain‑text credential of that key, and use it to authenticate as the higher‑privileged org_super_admin principal. This allows an attacker to assume an authority level far beyond what the original role permits, enabling full control over organizational resources, data, and configuration.
Affected Systems
Cap‑go capgo.app deployments that use any version prior to 12.267.1 are impacted. The issue is specific to the API key rotation functionality exposed through the PUT endpoint in those releases. All installations still running those versions should be considered vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, classifying it as High severity. The EPSS score is not available, so the exact exploitation likelihood cannot be quantified from the available data, but the lack of this score does not mitigate the risk posed by an attacker who already has apikey_manager privileges. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to be authenticated with the apikey_manager role, after which they can perform the rotation through the exposed API endpoint, retrieve the higher‑privileged key, and elevate their privileges.
OpenCVE Enrichment