Authentication Bypass in Capgo Affects Remote Access Security
CVE-2026-56299

6.9MEDIUM

Key Information:

Vendor

Capgo

Status
Vendor
CVE Published:
21 June 2026

What is CVE-2026-56299?

Capgo, prior to version 12.128.2, is susceptible to an authentication bypass vulnerability within the /build/upload/:jobId/* endpoint. This flaw enables unauthenticated attackers to send OPTIONS requests that circumvent authentication mechanisms, consequently invoking the tusProxy logic with incorrect credentials. The exploitation of this vulnerability permits attackers to generate persistent 500 errors, leading to request flooding and a denial of service. Organizations using Capgo versions before 12.128.2 are advised to update promptly to safeguard against these risks.

Affected Version(s)

Capgo 0 < 12.128.2

Capgo 12.128.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Judel777
.