CVE-2026-100615: Cap-go capgo.app before 12.267.1 Privilege Escalation via API Key Rotation
Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikeymanager to rotate a higher-privileged orgsuperadmin sibling key and recover its plaintext credential. Attackers with apikeymanager role can enumerate same-owner API keys, rotate a stronger sibling through the PUT endpoint, and obtain the replacement plaintext secret to authenticate as the higher-privileged principal.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
cap-go/capgo.appto a version that resolves this vulnerability.Fixed in 12.267.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs the apikey_manager role and access to API keys owned by the same owner. They can enumerate those keys and target a sibling key with org_super_admin privileges.
What access does exploitation provide?
The attacker can rotate the higher-privileged sibling key through the PUT endpoint and recover the replacement plaintext credential. That credential can then be used to authenticate as the higher-privileged principal.
Which versions are affected?
Cap-go capgo.app versions before 12.267.1 are affected.