SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-88861

HIGH · CVSS 8.3 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability allows an attacker to bypass multi-factor authentication (MFA) in Capgo applications, enabling unauthorized access to privileged role-based access control (RBAC) permissions using only the victim's password. This flaw occurs due to inadequate validation of session assurance levels in the Edge JWT middleware, which permits the creation of persistent app-scoped API keys that can perform sensitive operations even after the session is logged out. Organizations using Capgo should prioritize addressing this vulnerability, as it poses a significant risk to their security posture and could lead to unauthorized modifications in production environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-88861
Severity
HIGH
CVSS
8.3
EPSS
0.29%

Original NVD Description

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who knows only the victim's password can therefore authenticate, mint a persistent app-scoped app_admin API key that remains valid after the aal1 session is logged out, and perform privileged operations such as modifying production OTA channel configurations (validated by changing a public production channel from bundle 1.0.0 to 1.0.1), defeating the protection provided by MFA.