Impact
The vulnerability arises when Cap-go does not clear channel permission overrides after the last organization role binding for a user is removed. This oversight keeps stale permission records that grant channel‑specific rights, allowing a user who has otherwise lost base RBAC access to continue performing high‑impact actions such as updating production OTA versions. The flaw is a classic example of CWE‑863, causing unauthorized use of privilege.
Affected Systems
Cap-go’s Capgo.app platform is impacted. The advisory does not list specific version numbers; the issue exists in any release that retains channel permission overrides across role binding deletions. Administrators should verify that their deployment includes the vendor’s resolution.
Risk and Exploitability
With a CVSS score of 9.3 the risk is critical. Although the EPSS score is not available and the vulnerability is not listed in CISA KEV, the exploitation path is straightforward for an attacker who can trigger a role removal or create a stale override scenario internally. Successful exploitation would grant access to privileged actions without normal RBAC enforcement, leading to significant data integrity and availability compromise.
OpenCVE Enrichment