CVE-2026-88860: Cap-Go Capgo.app
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked to perform unauthorized actions like changing production OTA versions.
Affected products
- Cap-Go Capgo.app: any version
Published 2026-09-10. Last modified 2026-09-30.