Insecure Direct Object Reference in capgo by Cap-go
CVE-2026-100626

5.3MEDIUM

Key Information:

Vendor

Cap-go

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100626?

The capgo application up to version 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint. This vulnerability allows authenticated users to submit arbitrary storage paths for icons in the private images bucket. As a result, these users can gain access to service-role-signed URLs that are valid for up to 7 days. Consequently, they can read cross-tenant objects such as user avatars, organization logos, and app icons, bypassing authorization mechanisms. Attackers can leverage this vulnerability to access sensitive data that should not be available to unauthorized users.

Affected Version(s)

capgo.app 0 <= 12.128.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.