Authorization Bypass Vulnerability in Capgo Affects Channel Permissions
CVE-2026-88860
9.3CRITICAL
What is CVE-2026-88860?
The Capgo platform has a significant vulnerability that allows persistent channel permission overrides to remain active even after a user's base role binding has been deleted. This flaw enables attackers to retain channel-specific permissions, thereby allowing them to execute unauthorized actions such as altering production OTA versions. Proper cleanup mechanisms for role bindings are essential to prevent such exploits.
