CVE-2026-88860: Capgo Authorization Bypass via Stale Channel Permission Overrides

Published Sep 10, 2026
·
Updated

Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked to perform unauthorized actions like changing production OTA versions.

Affected Software

1 affected component
capgo

Event History

Sep 10, 2026
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Organizations using Capgo channel permission overrides are exposed when a user's final organization role binding is deleted. The deleted user may retain channel-specific permissions despite losing their base RBAC access.

2

What access does an attacker need to exploit it?

The attacker needs low-level authenticated access and must previously have channel-specific permission overrides. Exploitation depends on their last organization role binding being removed while those overrides remain active.

3

What can a retained user do?

A user with stale overrides can perform unauthorized actions allowed by those channel permissions, including changing production OTA versions. The reported impact includes confidentiality, integrity, and availability effects.

4

How can defenders identify potentially affected accounts?

Review users whose last organization role binding was deleted and check whether channel permission overrides remain assigned to them. Any active override associated with a user who no longer has base RBAC access should be treated as potentially unauthorized.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203