CyberRota Analysis
AI-GeneratedThe vulnerability allows users with the apikey_manager role to exploit insufficient validation during API key rotation, enabling them to rotate and recover plaintext credentials of higher-privileged org_super_admin keys. This could lead to unauthorized access and control over sensitive resources. Organizations using capgo.app versions prior to 12.267.1 should prioritize patching this issue to mitigate the risk of privilege escalation and data compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager to rotate a higher-privileged org_super_admin sibling key and recover its plaintext credential. Attackers with apikey_manager role can enumerate same-owner API keys, rotate a stronger sibling through the PUT endpoint, and obtain the replacement plaintext secret to authenticate as the higher-privileged principal.