SQL Injection Vulnerability in Cap-go Cloudflare Analytics Engine
CVE-2026-56221

7.1HIGH

Key Information:

Vendor

Cap-go

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-56221?

Cap-go versions prior to 12.128.2 are susceptible to multiple SQL injection vulnerabilities found in the Cloudflare Analytics Engine. These vulnerabilities occur when user-controlled data from API request bodies is directly incorporated into SQL query strings without adequate sanitization or parameterization. Authenticated users possessing read-level API key permissions can exploit this weakness by injecting arbitrary SQL through parameters such as deviceIds, search, version_name, cursor, and actions. This may enable them to access sensitive analytics data belonging to other users or applications, posing a significant risk to data integrity and privacy.

Affected Version(s)

capgo 0 < 12.128.2

capgo 12.128.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.