Authentication Bypass in Capgo Backend for API Key Management
CVE-2026-88862

8.7HIGH

Key Information:

Vendor

Cap-go

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88862?

The Capgo backend does not properly validate parent-child delegation when handling the x-limited-key-id header, allowing attackers to exploit API key mismanagement. In version 12.242.4, an authenticated API key manager can utilize the numeric ID of a higher-privileged key without proper authorization, effectively gaining access to enhanced permissions. This flaw stems from the mishandling of API keys as independent RBAC principals, which enables manipulation of user roles and access rights without needing the associated secret.

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Judel777
.