Authentication Bypass in Capgo Affects Remote Access Security
CVE-2026-56299
6.9MEDIUM
What is CVE-2026-56299?
Capgo, prior to version 12.128.2, is susceptible to an authentication bypass vulnerability within the /build/upload/:jobId/* endpoint. This flaw enables unauthenticated attackers to send OPTIONS requests that circumvent authentication mechanisms, consequently invoking the tusProxy logic with incorrect credentials. The exploitation of this vulnerability permits attackers to generate persistent 500 errors, leading to request flooding and a denial of service. Organizations using Capgo versions before 12.128.2 are advised to update promptly to safeguard against these risks.
Affected Version(s)
Capgo 0 < 12.128.2
Capgo 12.128.2
