Authorization Bypass Vulnerability in Capgo's API Key Management
CVE-2026-56225

8.7HIGH

Key Information:

Vendor

Capgo

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-56225?

An authorization bypass vulnerability exists in Capgo's public API key management handlers, affecting versions prior to 12.128.2. This flaw allows API keys created with mode=all and restricted to a single app to bypass checks for app scope. Consequently, this permits an app-scoped key to enumerate, update, and delete sibling API keys that belong to the same account, even if those keys operate outside the declared app scope. This security lapse can lead to unauthorized tampering with account-level credentials.

Affected Version(s)

Capgo 0 < 12.128.2

Capgo 12.128.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Judel777
.