OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100614

HIGH · CVSS 8.8 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects Capgo versions prior to 12.244.1, where an authenticated attacker can exploit a cross-tenant integrity flaw in the metadata-cleaning worker. By manipulating image object keys from mutable database rows, attackers can modify metadata of cross-tenant image objects without authorization, leading to potential data integrity issues. Organizations using Capgo should prioritize patching this vulnerability to prevent unauthorized metadata modifications and protect tenant data integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100614
Severity
HIGH
CVSS
8.8
EPSS
0.32%

Original NVD Description

Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenant's image key in a row they control, causing the service-role worker to download and re-upload that object with sanitized metadata. Attackers can silently modify metadata in cross-tenant image objects by supplying known victim keys during authorized row updates, bypassing storage access controls through the confused-deputy metadata worker.