CVE-2026-56300 Details
Description
Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity oracles and user UUID disclosure. Unauthenticated attackers using the public API key can validate leaked keys, enumerate users and apps, and determine permission levels, significantly increasing the actionability of compromised credentials.
A vulnerability exists in Capgo versions prior to 12.128.2, where unauthenticated security definer RPC functions 'get_user_id' and 'get_org_perm_for_apikey' expose oracles for API key validity, user UUIDs, and organizational permissions. This allows attackers to validate leaked API keys, enumerate users and applications, and assess permission levels, thereby increasing the risk associated with compromised credentials.
Users are advised to update to Capgo version 12.128.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cap-go/capgo/security/advisories/GHSA-7r6g-whg3-5mm4 | CISA-ADP | AdvisoryExploitVendor |
| https://github.com/Cap-go/capgo/security/advisories/GHSA-7r6g-whg3-5mm4 | [email protected] | AdvisoryExploitVendor |
| https://www.vulncheck.com/advisories/capgo-unauthenticated-api-key-validity-and-permission-oracle-via-rpc-functions | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Capgo | < 12.128.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion