Information Disclosure Vulnerability in Capgo by Capgo
CVE-2026-56282
6.9MEDIUM
What is CVE-2026-56282?
Capgo prior to version 12.128.2 exposes a vulnerable /replication endpoint that allows unauthenticated attackers to access sensitive internal PostgreSQL replication data. This includes details such as replication slot names, confirmed_flush_lsn, and restart_lsn values, which can be exploited for reconnaissance. The lack of authentication enables unauthorized access to critical infrastructure telemetry, potentially leading to further security breaches.
Affected Version(s)
Capgo 0 < 12.128.2
Capgo 12.128.2
