Impact
Cap-go's channel_permission_overrides field fails to confirm that users added to overrides belong to the same organization as the channel. This oversight allows any authenticated application or organization administrator to insert override rows containing arbitrary external user identifiers, granting those users channel‑specific permissions—such as the ability to promote bundles—to channels they would normally be unable to access. The consequence of this flaw is that non‑members of an organization can obtain powerful, channel‑level capabilities solely through administrative rights, effectively elevating an attacker’s privileges within the affected service.
Affected Systems
The vulnerability is present in Cap-go’s capgo.app product. Specific affected product versions are not listed in the available data; administrators should check the latest releases for the presence of remediation changes.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, classifying it as high severity. Exploitation requires authenticated admin rights, so the attack vector is limited to privileged users. No EPSS score is reported and it is not listed in the CISA KEV catalog, but the high CVSS indicates significant risk when the vulnerability is present. The path to exploitation is straightforward once admin privileges are obtained: create an override entry referencing an external UUID and assign channel‑scoped permissions.
OpenCVE Enrichment