CVE-2026-56318 Details
Description
Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endpoint that returns different error responses for malformed, non-existent, and existing organization IDs. Unauthenticated attackers can enumerate valid organization UUIDs by observing response status codes and error messages, allowing confirmation of organization existence.
An information disclosure vulnerability has been identified in Capgo versions prior to 12.128.2. The issue resides in the '/private/validate_password_compliance' endpoint, which returns varying error responses based on the validity and existence of organization IDs. This discrepancy allows unauthenticated attackers to enumerate valid organization UUIDs by analyzing response status codes and error messages, thereby confirming the existence of organizations.
Normalize the error responses for unauthenticated requests to provide a generic error message for invalid or unknown organization IDs, avoiding distinctions that could be exploited.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cap-go/capgo/security/advisories/GHSA-fwwh-rqv7-6pjf | CISA-ADP | ExploitTechnical DescriptionVendor |
| https://github.com/Cap-go/capgo/security/advisories/GHSA-fwwh-rqv7-6pjf | [email protected] | ExploitTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/capgo-information-disclosure-via-private-validate-password-compliance-endpoint | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Capgo | < 12.128.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion