Authentication Bypass in Capgo Backend for API Key Management
CVE-2026-88862
8.7HIGH
What is CVE-2026-88862?
The Capgo backend does not properly validate parent-child delegation when handling the x-limited-key-id header, allowing attackers to exploit API key mismanagement. In version 12.242.4, an authenticated API key manager can utilize the numeric ID of a higher-privileged key without proper authorization, effectively gaining access to enhanced permissions. This flaw stems from the mishandling of API keys as independent RBAC principals, which enables manipulation of user roles and access rights without needing the associated secret.
