Insecure Direct Object Reference in capgo by Cap-go
CVE-2026-100626
5.3MEDIUM
What is CVE-2026-100626?
The capgo application up to version 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint. This vulnerability allows authenticated users to submit arbitrary storage paths for icons in the private images bucket. As a result, these users can gain access to service-role-signed URLs that are valid for up to 7 days. Consequently, they can read cross-tenant objects such as user avatars, organization logos, and app icons, bypassing authorization mechanisms. Attackers can leverage this vulnerability to access sensitive data that should not be available to unauthorized users.
Affected Version(s)
capgo.app 0 <= 12.128.2
