Unauthenticated API Vulnerability in Capgo Affects User Identity Disclosure
CVE-2026-56242
8.7HIGH
What is CVE-2026-56242?
Capgo prior to version 12.128.2 is susceptible to an unauthenticated vulnerability within the RPC function 'get_identity_apikey_only'. This flaw allows attackers to query the function with either valid or invalid API keys, which can confirm API key validity and reveal user identifiers linked to those keys. Additionally, this disclosure can be exploited alongside other exposed RPC endpoints, such as 'get_orgs_v6', to access sensitive organization membership details and personally identifiable information (PII) of management emails.
Affected Version(s)
Capgo 0 < 12.128.2
Capgo 12.128.2
