{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acap_gocapgo_app/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cap_go:capgo_app:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-100617"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["capgo.app","capgo.app (\u003c= 12.129.0)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","cloud-security","privilege-escalation","vulnerability","cloud","ota-updates","rce","exfiltration","rbac-flaw"],"_cs_type":"advisory","_cs_vendors":["Cap-go","Capgo"],"content_html":"\u003cp\u003eCap-go capgo.app contains a critical authorization vulnerability (CVE-2026-100617) stemming from improper input validation within the \u003ccode\u003echannel_permission_overrides\u003c/code\u003e function. The application fails to verify that user principals referenced in permission overrides actually belong to the target organization. This allows an authenticated administrator (at either the application or organization level) to maliciously associate arbitrary external user UUIDs with internal channel permissions. An attacker can leverage this flaw to grant sensitive permissions, such as \u003ccode\u003echannel.promote_bundle\u003c/code\u003e, to external entities that should have no access to the organization's private channels. This creates a significant risk of unauthorized access to sensitive deployment bundles and internal processes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized granting of administrative channel permissions to users outside of the intended organization. This can lead to unauthorized modification of deployment bundles, unauthorized channel management, and potential supply chain compromise if external users gain the ability to influence code or asset promotion within the victim organization's infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit organizational audit logs for suspicious additions to \u003ccode\u003echannel_permission_overrides\u003c/code\u003e where the assigned UUID does not correspond to an existing member of the organization.\u003c/li\u003e\n\u003cli\u003eReview all current permission overrides within the capgo.app management interface to identify and remove entries involving unrecognized or external UUIDs.\u003c/li\u003e\n\u003cli\u003eUpdate capgo.app to the latest version that implements strict validation of principal organization membership.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T17:00:02Z","date_published":"2026-09-26T15:02:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-capgo-auth-bypass/","summary":"A vulnerability in capgo.app allows authenticated administrators to bypass organization boundaries by assigning channel-specific permissions to arbitrary external user UUIDs.","title":"Authorization Bypass in capgo.app via Channel Permission Overrides","url":"https://feed.craftedsignal.io/briefs/2026-09-capgo-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:cap_go:capgo_app:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}