PT-2026-54026 · Cap Go · Cap-Go

·

CVE-2026-56249

·

Published

2026-06-30

·

Updated

2026-06-30

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description An authorization bypass exists in the channel creation endpoint. Authenticated users with app.create channel permission can overwrite existing channels by reusing their names. This is possible due to a logic mismatch between existence validation and upsert operations, which allows attackers to reassign channel ownership and modify critical production channel configurations.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56249
GHSA-VJ24-J594-3WV3

Affected Products

Cap-Go