CVE-2026-56246
Capgo
Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped API key (limited_to_orgs) inherits its owner-user's permissions, allowing destructive cross-organization actions. When a user is an admin in two organizations and creates a write-mode API key restricted to one organization, that key can still perform destructive operations (e.g., DELETE /organization, DELETE /organization/members) against another organization. The root cause is route-level authorization (rbac_check_permission_direct) that evaluates the key owner's user priv...
- CVSS
- 7.2
- EPSS
- 0.22% 12.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.08