PT-2026-51768 · Cap Go · Cap-Go

CVE-2026-56237

·

Published

2026-06-24

·

Updated

2026-06-24

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description Broken authentication exists in the API key generation mechanism. API keys are exposed in frontend requests, and the backend does not validate that keys are securely generated or bound to the authenticated user. An attacker can tamper with the API key parameter in the generation request and provide arbitrary values to generate custom API keys without proper authorization, potentially leading to unauthorized access to protected endpoints.
Recommendations Update to version 12.128.2.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56237
GHSA-22W2-MX2H-4FR7

Affected Products

Cap-Go