Description
Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared during role binding deletion. Attackers can exploit this by maintaining a previously granted super_admin role to enumerate and bulk delete non-compliant bundles across the entire organization indefinitely.
Published: 2026-07-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Capgo before version 12.128.2 has a privilege escalation flaw that allows a user who has been demoted from the super_admin role to retain access to the delete_non_compliant_bundles and count_non_compliant_bundles RPCs. This occurs because the org_users.user_right column is not cleared when a role binding is deleted, leaving stale privileges. As a result, an attacker can continuously enumerate and bulk delete non‑compliant bundles across the organization.

Affected Systems

The vulnerability affects Capgo installations that run any version earlier than 12.128.2. It specifically impacts the Capgo application hosted under the Capgo:Capgo product line.

Risk and Exploitability

The CVSS score of 7.2 reflects moderate to high risk. The EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listedV catalog. The likely attack vector requires an account that has been demoted from super_admin but still retains legacy rights. An attacker can leverage these stale privileges to enumerate and bulk delete non‑compliant bundles across the organization, compromising data integrity.

Generated by OpenCVE AI on August 1, 2026 at 11:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Capgo to version 12.128.2 or later to apply the fix that clears stale org_users.user_right entries when role bindings are deleted.
  • For environments that cannot update immediately, identify users whose super_admin role was revoked and clear their org_users.user_right values manually or reassign roles to properly remove legacy privileges, ensuring they no longer have access to delete_non_compliant_bundles or count_non_compliant_bundles RPCs.
  • Restrict or disable the delete_non_compliant_bundles and count_non_compliant_bundles RPCs for non‑super_admin users through configuration or role adjustments, and monitor audit logs for unauthorized usage.

Generated by OpenCVE AI on August 1, 2026 at 11:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Cap-go
Cap-go cap-go
Vendors & Products Cap-go
Cap-go cap-go

Sun, 12 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared during role binding deletion. Attackers can exploit this by maintaining a previously granted super_admin role to enumerate and bulk delete non-compliant bundles across the entire organization indefinitely.
Title Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T14:43:46.193Z

Reserved: 2026-06-19T21:50:06.625Z

Link: CVE-2026-56241

cve-icon Vulnrichment

Updated: 2026-07-14T14:43:27.730Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:15:03Z

Weaknesses