<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:cap_go:capgo_app:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acap_gocapgo_app/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 26 Sep 2026 15:02:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acap_gocapgo_app/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in capgo.app via Channel Permission Overrides</title><link>https://feed.craftedsignal.io/briefs/2026-09-capgo-auth-bypass/</link><pubDate>Sat, 26 Sep 2026 15:02:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-capgo-auth-bypass/</guid><description>A vulnerability in capgo.app allows authenticated administrators to bypass organization boundaries by assigning channel-specific permissions to arbitrary external user UUIDs.</description><content:encoded><![CDATA[<p>Cap-go capgo.app contains a critical authorization vulnerability (CVE-2026-100617) stemming from improper input validation within the <code>channel_permission_overrides</code> function. The application fails to verify that user principals referenced in permission overrides actually belong to the target organization. This allows an authenticated administrator (at either the application or organization level) to maliciously associate arbitrary external user UUIDs with internal channel permissions. An attacker can leverage this flaw to grant sensitive permissions, such as <code>channel.promote_bundle</code>, to external entities that should have no access to the organization's private channels. This creates a significant risk of unauthorized access to sensitive deployment bundles and internal processes.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the unauthorized granting of administrative channel permissions to users outside of the intended organization. This can lead to unauthorized modification of deployment bundles, unauthorized channel management, and potential supply chain compromise if external users gain the ability to influence code or asset promotion within the victim organization's infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering teams:</p>
<ul>
<li>Audit organizational audit logs for suspicious additions to <code>channel_permission_overrides</code> where the assigned UUID does not correspond to an existing member of the organization.</li>
<li>Review all current permission overrides within the capgo.app management interface to identify and remove entries involving unrecognized or external UUIDs.</li>
<li>Update capgo.app to the latest version that implements strict validation of principal organization membership.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authorization-bypass</category><category>cloud-security</category><category>privilege-escalation</category><category>vulnerability</category><category>cloud</category><category>ota-updates</category><category>rce</category><category>exfiltration</category><category>rbac-flaw</category></item></channel></rss>