PT-2026-54035 · Cap Go · Cap-Go

·

CVE-2026-56328

·

Published

2026-06-30

·

Updated

2026-06-30

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description The software allows multiple public channels for the same application and platform to exist at the same time. When requests are made to the '/updates' endpoint without specifying a defaultChannel, they implicitly resolve to a single hidden winner channel. This allows an authorized app or channel manager to create an ambiguous default update state and silently influence which bundle unnamed clients receive, which compromises release routing integrity and predictability.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56328
GHSA-3CMP-PM5X-8464

Affected Products

Cap-Go