Unauthenticated API Vulnerability in Capgo Affects User Identity Disclosure
CVE-2026-56242

8.7HIGH

Key Information:

Vendor

Capgo

Status
Vendor
CVE Published:
21 June 2026

What is CVE-2026-56242?

Capgo prior to version 12.128.2 is susceptible to an unauthenticated vulnerability within the RPC function 'get_identity_apikey_only'. This flaw allows attackers to query the function with either valid or invalid API keys, which can confirm API key validity and reveal user identifiers linked to those keys. Additionally, this disclosure can be exploited alongside other exposed RPC endpoints, such as 'get_orgs_v6', to access sensitive organization membership details and personally identifiable information (PII) of management emails.

Affected Version(s)

Capgo 0 < 12.128.2

Capgo 12.128.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Judel777
.