OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100617

HIGH · CVSS 8.8 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated app or organization administrators to improperly grant channel permissions to external users by inserting arbitrary UUIDs into channel_permission_overrides, bypassing organizational membership checks. This could lead to unauthorized access to sensitive channel functionalities, posing a significant risk to data integrity and confidentiality. Organizations utilizing the affected Cap-go application should prioritize remediation to prevent potential exploitation by malicious insiders or compromised admin accounts.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100617
Severity
HIGH
CVSS
8.8
EPSS
0.30%

Original NVD Description

Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped permissions such as channel.promote_bundle to users outside the organization.