Description
Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can modify sensitive channel attributes such as public, allow_emulator, and security-related flags outside intended application routes.
Published: 2026-07-10
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Capgo versions prior to 12.128.2 contain an authorization bypass that allows write‑scoped API keys to mutate protected channel configuration fields. The bug arises from a null authentication check in the immutability trigger of PostgREST. Because the trigger does not verify that the API key has permission to change these fields, an attacker can alter sensitive attributes such as public, allow_emulator, and security‑related flags outside the normal application routes. This enables unauthorized modification of channel behavior and potentially opens additional attack surfaces.

Affected Systems

The vulnerability affects all installations of Capgo running a server component version earlier than 12.128.2. Any deployment of the affected server is at risk, as no specific platform variants are indicated.

Risk and Exploitability

The CVSS score of 7.1 places the flaw in the high severity range. Because it is tied to the possession of a write‑scoped API key, exploitation requires an attacker to already have such a key; however, once an attacker has one, no additional authentication is needed to change channel settings. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting that there is currently no known active exploitation. Nonetheless, the scope of the impact – altering channel security flags – warrants immediate action.

Generated by OpenCVE AI on July 29, 2026 at 10:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Capgo to version 12.128.2 or later, where the immutability check has been restored.
  • Revoke or rotate any write‑scoped API keys that have the authority to modify channel configuration, ensuring that only trusted routes can change protected fields.
  • Review and audit channel configurations for any unexpected modifications and monitor logs for anomalous changes.

Generated by OpenCVE AI on July 29, 2026 at 10:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Cap-go
Cap-go cap-go
Vendors & Products Cap-go
Cap-go cap-go

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can modify sensitive channel attributes such as public, allow_emulator, and security-related flags outside intended application routes.
Title Capgo - Channel Configuration Mutation via Write-Scoped API Keys
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-10T14:56:52.599Z

Reserved: 2026-06-20T13:13:56.012Z

Link: CVE-2026-56335

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:00:13Z

Weaknesses