CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100614

HIGHCVSS 8.8NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenant's image key in a row they control, causing the service-role

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100614 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100614

HIGHCVSS 8.8NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenant's image key in a row they control, causing the service-role

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]