Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareKey function. Attackers can bypass subkey scope restrictions by referencing their own subkeys, causing all downstream route handlers to use the unrestricted parent key instead of the scoped subkey.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-24 13:16
Updated : 2026-06-25 14:03
NVD link : CVE-2026-56232
Mitre link : CVE-2026-56232
CVE.ORG link : CVE-2026-56232
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
