PT-2026-51766 · Cap Go · Cap-Go

Judel777

·

Published

2026-06-24

·

Updated

2026-06-24

·

CVE-2026-56231

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId endpoints. The handlers authorize the request based only on the attacker-controlled app id supplied in the request body and never verify that the jobId in the URL belongs to that app id (or the same tenant/org) before issuing privileged builder commands with the server-held builder API key. An authenticated user with the app.build native permission for any app they control can start or cancel arbitrary builder jobs belonging to other tenants by supplying a victim jobId, resulting in cross-tenant build sabotage (denial of service), unauthorized compute actions, and potential billing impact.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56231

Affected Products

Cap-Go