PT-2026-51766 · Cap Go · Cap-Go
Judel777
·
Published
2026-06-24
·
Updated
2026-06-24
·
CVE-2026-56231
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H |
Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId endpoints. The handlers authorize the request based only on the attacker-controlled app id supplied in the request body and never verify that the jobId in the URL belongs to that app id (or the same tenant/org) before issuing privileged builder commands with the server-held builder API key. An authenticated user with the app.build native permission for any app they control can start or cancel arbitrary builder jobs belonging to other tenants by supplying a victim jobId, resulting in cross-tenant build sabotage (denial of service), unauthorized compute actions, and potential billing impact.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go