CVE-2026-88860
nicheStale channel permission overrides in Capgo let revoked users alter OTA updates
Capgo, an over-the-air (OTA) update platform for mobile apps, fails to remove channel-specific permission overrides when a user's last organization role binding is deleted, an incorrect-authorization flaw tracked as CWE-863. The condition is triggered when a user's final role binding in an organization is removed but their per-channel overrides are left in place in the system. The revoked user can then keep exercising channel-level permissions to perform unauthorized actions, most notably changing production OTA update versions that the organization's app users receive. Organizations using Capgo's channel/RBAC management (cloud service or self-hosted deployments) that have removed former users are affected. No public proof-of-concept or in-the-wild exploitation is known and the issue is not in CISA's KEV; CVSS 4.0 rates it 9.3 critical.
What to do: Audit existing channel permission overrides and delete any belonging to users who no longer hold an organization role binding, then upgrade Capgo (cloud or self-hosted) to the patched release when one becomes available, as no fixed version is specified in the source data. Until patched, re-verify that removed users cannot perform channel actions such as changing production OTA update versions.
| Capgo (OTA update platform with channel/RBAC permission management) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked to perform unauthorized actions like changing production OTA versions.
- Weakness
- CWE-863
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.