Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026
Capgo - Cross-Organization Authorization Bypass via Scoped API Key Privilege Inheritance
CVE-2026-56246
Description
Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped API key (limited_to_orgs) inherits its owner-user's permissions, allowing destructive cross-organization actions. When a user is an admin in two organizations and creates a write-mode API key restricted to one organization, that key can still perform destructive operations (e.g., DELETE /organization, DELETE /organization/members) against another organization. The root cause is route-level authorization (rbac_check_permission_direct) that evaluates the key owner's user privileges before enforcing the API key's limited_to_orgs scope.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-ccm4-hf72-p28mmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-cross-organization-authorization-bypass-via-scoped-api-key-privilege-inheritancemitrethird-party-advisory
News mentions
0No linked articles in our index yet.