{"id":"CVE-2026-100615","published":"2026-09-26T14:16:42.193","lastModified":"2026-09-28T20:57:50.143","description":"Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager to rotate a higher-privileged org_super_admin sibling key and recover its plaintext credential. Attackers with apikey_manager role can enumerate same-owner API keys, rotate a stronger sibling through the PUT endpoint, and obtain the replacement plaintext secret to authenticate as the higher-privileged principal.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-269"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-8h52-44r7-w343","tags":[]},{"url":"https://www.vulncheck.com/advisories/cap-go-capgo-app-before-12.267.1-privilege-escalation-via-api-key-rotation","tags":[]},{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-8h52-44r7-w343","tags":[]}],"exploitRefs":[{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-8h52-44r7-w343","tags":[]},{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-8h52-44r7-w343","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an apikey_manager to rotate a higher-privileged org_super_admin API key, leading to credential recovery. This matters because it enables privilege escalation and unauthorized access.","exploitability":"Exploitation requires an attacker to have the apikey_manager role and knowledge of the API key management process. The exploit is moderately hard to execute.","blast_radius":"If exploited, this could lead to full control over the org_super_admin account, compromising the entire system and sensitive data.","remediation":"Upgrade to Cap-go capgo.app 12.267.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","privilege-escalation","api"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:02:17.568Z"}}