Broken Access Control in Cap Video Management Software by Cap Software
CVE-2026-69113
5.3MEDIUM
What is CVE-2026-69113?
In Cap v0.3.1, a broken access control vulnerability exists in the POST /api/video/comment endpoint. This flaw allows authenticated users to post comments on private videos that do not belong to them by simply supplying an arbitrary videoId in the request body. Attackers could exploit this vulnerability to inject unwanted comments into private video content, notify the original video owner via comment notifications, and potentially enumerate valid video IDs based on observable differences in the server responses.
Affected Version(s)
Cap 0 <= 0.3.1
