CVE-2026-88860: Capgo Authorization Bypass via Stale Channel Permission Overrides
Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked to perform unauthorized actions like changing production OTA versions.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Organizations using Capgo channel permission overrides are exposed when a user's final organization role binding is deleted. The deleted user may retain channel-specific permissions despite losing their base RBAC access.
What access does an attacker need to exploit it?
The attacker needs low-level authenticated access and must previously have channel-specific permission overrides. Exploitation depends on their last organization role binding being removed while those overrides remain active.
What can a retained user do?
A user with stale overrides can perform unauthorized actions allowed by those channel permissions, including changing production OTA versions. The reported impact includes confidentiality, integrity, and availability effects.
How can defenders identify potentially affected accounts?
Review users whose last organization role binding was deleted and check whether channel permission overrides remain assigned to them. Any active override associated with a user who no longer has base RBAC access should be treated as potentially unauthorized.