CVE-2026-56225

Published
View on NVD ↗
CVSS v3
8.3
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/delete/post). API keys created with mode=all but restricted to a single app via limited_to_apps are only checked for limited_to_orgs and not for limited_to_apps, so an app-scoped key can enumerate, update, and delete sibling API keys belonging to the same account that are outside its declared app scope, enabling tampering with account-level credentials.

Console, Backend and CLI to manage Capgo Instant update and Native build for Capacitor apps
GitHubGitHub
198