Impact
Capgo versions prior to 12.128.2 allow an attacker with administrative role in one organization to create role bindings for applications belonging to other organizations. The library fails to confirm that the supplied app_id actually belongs to the organization of the requester, enabling the attacker to grant themselves read or write access to victim applications. This results in unauthorized access and potential modification of application data, code, and configuration.
Affected Systems
Capgo (the open‑source mobile update platform) is affected in deployments using any version earlier than 12.128.2. The issue is present in the POST /private/role_bindings endpoint that manages application‑scoped role bindings.
Risk and Exploitability
The CVSS score of 8.6 classifies this flaw as high severity. Although the EPSS score is not available, the vulnerability is remotely exploitable through a web API that requires a valid administrative token for the source organization. The lack of inclusion in the CISA KEV catalog suggests no known exploitation to date, but the ability to re‑configure access for apps in other orgs makes it a serious privilege escalation that could lead to data leaks or service disruption.
OpenCVE Enrichment