Impact
Capgo versions earlier than 12.128.2 contain a flaw in the organization‑security‑settings component. The server skips field‑level validation for sensitive parameters such as max_apikey_expiration_days, allowing an authenticated organization administrator to set arbitrary values via browser‑side updates. This bypasses backend checks and lets an admin persist insecure policy states that undermine the intended security posture.
Affected Systems
Capgo installations using any release older than 12.128.2 are affected. The vulnerable code resides in the public.orgs database table accessed through the organization‑security‑settings endpoint, and any deployment that exposes the browser‑side organization settings interface to authenticated admins is susceptible.
Risk and Exploitability
The CVSS score of 5.3 signifies moderate risk. No EPSS score is published, so the likelihood of exploitation remains unspecified. The vulnerability is not registered in the CISA KEV catalog. An attacker must be a legitimate organization administrator and must manipulate the browser to submit altered settings; the bypass removes the server guard, permitting persistent misconfiguration that can weaken API key expiry rules and expose the organization to privilege escalation.
OpenCVE Enrichment