PT-2026-51144 · Cap Go · Cap-Go

·

CVE-2026-56325

·

Published

2026-06-20

·

Updated

2026-06-21

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description The preview subdomain resolver uses ILIKE pattern matching instead of exact matching for app id lookup. This allows underscore characters within the app id to function as SQL wildcards. An attacker can create applications with app id values that differ by only one character at the underscore positions, leading to unintended pattern matches. This can result in the disruption of preview functionality for legitimate applications or cause confusion regarding the app id.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56325
GHSA-CW88-CH2J-8VQJ

Affected Products

Cap-Go