CVE-2026-56323: high-severity vulnerability in Capgo
Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.6%
exploitation probability
0.6%top 51% of all CVEs
observed exploitation
nono source reports it
Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attackers to enumerate non-public channel names and determine app existence and subscription status. Remote attackers can send GET requests with arbitrary app_id parameters to disclose internal rollout channels, enumerate valid applications across tenants, and leak billing status without authentication or device binding.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Capgo · CapgoRelated CVEs — Capgo
In the same product, most dangerous first.
CVE-2026-56299MEDIUMCapgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload EndpointEPSS 0.7%CVE-2026-56233HIGHCapgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload ProxyEPSS 0.6%CVE-2026-56238HIGHCapgo - Unauthenticated Information Disclosure via PostgREST global_stats EndpointEPSS 0.6%CVE-2026-56286HIGHCapgo - Account Deletion Without Password ConfirmationEPSS 0.5%CVE-2026-56222HIGHCapgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindingsEPSS 0.5%CVE-2026-56305HIGHCapgo - Authentication Bypass in Password Change via Missing Current Password ValidationEPSS 0.5%