Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped permissions such as channel.promote_bundle to users outside the organization. | |
| Title | Cap-go capgo.app Authorization Bypass via channel_permission_overrides | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T13:22:57.529Z
Reserved: 2026-09-26T02:31:07.601Z
Link: CVE-2026-100617
No data.
Status : Received
Published: 2026-09-26T14:16:42.467
Modified: 2026-09-26T14:16:42.467
Link: CVE-2026-100617
No data.
OpenCVE Enrichment
No data.