PT-2026-51767 · Cap Go · Cap-Go

·

CVE-2026-56232

·

Published

2026-06-24

·

Updated

2026-06-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description The middlewareKey() function fails to enforce limited to orgs and limited to apps constraints on subkeys provided through the x-limited-key-id header. This allows attackers to bypass subkey scope restrictions by referencing their own subkeys, which results in downstream route handlers utilizing the unrestricted parent key instead of the intended scoped subkey.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56232
GHSA-2H89-VCVX-5PVH

Affected Products

Cap-Go