Impact
Capgo backend systems through version 12.242.4 allow an attacker to bypass authentication controls by supplying a numeric API key ID in the x-limited-key-id header. The middleware that interprets this header fails to verify that the supplied key belongs to the same privileged parent, enabling an apikey_manager key that normally has no application access to substitute the identity of a higher‑privilege key belonging to the same owner. This flaw effectively grants the attacker app_admin permissions without the corresponding secret, raising the confidentiality, integrity, and availability of the application.
Affected Systems
Capgo (capgo.app) backend as distributed via the Cap‑Go framework, specifically all releases up to and including 12.242.4. No other versions are presently known to be affected.
Risk and Exploitability
The CVSS score of 8.7 classifies the vulnerability as high severity. Because no EPSS value is available, the exact exploitation probability cannot be quantified, but the flaw permits a privileged escalation that can be achieved over a network interface that processes the x-limited-key-id header. The vulnerability does not appear in the CISA KEV catalog, and no published public exploit scripts exist, yet the path to exploitation involves only standard HTTP request manipulation and the use of a valid apikey_manager key.
OpenCVE Enrichment