CVE-2026-100620
Last modified
CVE-2026-100620 is a low-severity vulnerability rated 3.8/10 on the CVSS scale. Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL (passed as developerAccountPermissions in the Android Publisher API User create request), even though the user-facing flow states the service account is invited into a single confirmed app with release-only permissions.
Description
Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL (passed as developerAccountPermissions in the Android Publisher API User create request), even though the user-facing flow states the service account is invited into a single confirmed app with release-only permissions. As a result, anyone who obtains the generated service account key (PLAY_CONFIG_JSON) can create, edit, and delete draft apps across the entire Google Play developer account rather than being limited to the selected package. No patched version was available at the time of publication.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Cap-go | @capgo/cli | <= 7.98.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-100620?
How severe is CVE-2026-100620?
How do I fix CVE-2026-100620?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100615Cap-go capgo.app before 12.267.1 fails to validate target AP…8.8
- CVE-2026-100616capgo.app is an over-the-air update platform for Capacitor a…5.5
- CVE-2026-100617Cap-go capgo.app fails to validate that principals in channe…8.8
- CVE-2026-100618Capgo (capgo.app) is affected by an authorization flaw in th…8.5
- CVE-2026-100619Capgo (capgo.app) blocks direct user inserts into the public…8.8
- CVE-2026-10062A vulnerability was determined in TRENDnet TEW-432BRP 3.10B2…9.8
- CVE-2026-100621Capgo (capgo.app) contains an incomplete access-control/cont…4.3
- CVE-2026-100622capgo.app through 12.129.0 fails to verify deletion status w…7.5
- CVE-2026-100623Capgo (capgo.app) exposes the legacy membership table public…8.8
- CVE-2026-100624Capgo.app before 12.264.5 does not enforce upload expiry or …5.4
- CVE-2026-100625Capgo (capgo.app) exposes a native build TUS upload proxy (s…7.1
- CVE-2026-100626capgo through 12.128.2 contains an insecure direct object re…4.3
Are you affected by CVE-2026-100620?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
