Denial of Service Vulnerability in Capgo by Capgo
CVE-2026-56255

5.3MEDIUM

Key Information:

Vendor

Capgo

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-56255?

Capgo prior to version 12.128.2 is susceptible to a denial of service issue in the POST /app/demo endpoint. Authenticated users possessing organization write permissions can exploit this vulnerability to generate an unlimited number of demo applications. This absence of rate limiting and quota enforcement allows attackers to invoke this endpoint repetitively, leading to approximately 138 database write operations for every request. Such activities can severely degrade performance, increase operational costs, and lead to overall service instability.

Affected Version(s)

Capgo 0 < 12.128.2

Capgo 12.128.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Judel777
.