PT-2026-51768 · Cap Go · Cap-Go
CVE-2026-56237
·
Published
2026-06-24
·
Updated
2026-06-24
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
Broken authentication exists in the API key generation mechanism. API keys are exposed in frontend requests, and the backend does not validate that keys are securely generated or bound to the authenticated user. An attacker can tamper with the API key parameter in the generation request and provide arbitrary values to generate custom API keys without proper authorization, potentially leading to unauthorized access to protected endpoints.
Recommendations
Update to version 12.128.2.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go