CVE-2026-56216: Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey
Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint unrestricted keys by setting empty limits. Attackers with a compromised app-limited key can create an unrestricted key with org-wide access to resources like app listings and other protected endpoints.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56216?
The severity of CVE-2026-56216 is rated high with a score of 8.8.
How do I fix CVE-2026-56216?
To fix CVE-2026-56216, update Capgo to a version later than 12.128.2.
What is the risk associated with CVE-2026-56216?
CVE-2026-56216 poses a risk of scope escalation, allowing the creation of unrestricted API keys from app-limited keys.
What does the vulnerability in CVE-2026-56216 affect?
CVE-2026-56216 affects the Capgo software, specifically through the POST /functions/v1/apikey endpoint.
Who is impacted by CVE-2026-56216?
Users of Capgo who utilize app-limited API keys are potentially impacted by CVE-2026-56216.