CVE-2026-56225: Capgo - Authorization Bypass in API Key Management via App-Limited Keys
Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/delete/post). API keys created with mode=all but restricted to a single app via limitedtoapps are only checked for limitedtoorgs and not for limitedtoapps, so an app-scoped key can enumerate, update, and delete sibling API keys belonging to the same account that are outside its declared app scope, enabling tampering with account-level credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56225?
The severity of CVE-2026-56225 is high with a score of 8.3.
How does CVE-2026-56225 affect API key management in Capgo?
CVE-2026-56225 allows an authorization bypass in public API key management handlers, compromising app-limited keys.
How can I mitigate the risk of CVE-2026-56225?
Mitigation of CVE-2026-56225 involves updating Capgo to version 12.128.2 or later to address the authorization bypass.
What types of systems are affected by CVE-2026-56225?
CVE-2026-56225 affects all systems using Capgo versions prior to 12.128.2 that utilize app-limited API keys.
Is it necessary to take immediate action on CVE-2026-56225?
Yes, it is crucial to take immediate action to update Capgo and prevent potential unauthorized access through the vulnerability.