PT-2026-57174 · Cap Go · Cap-Go

·

CVE-2026-56335

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description An authorization bypass exists where write-scoped API keys can directly mutate protected channel configuration fields via PostgREST. This occurs due to a null authentication check in the immutability trigger, allowing attackers with write API keys to modify sensitive channel attributes such as public, allow emulator, and security-related flags outside of the intended application routes.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56335
GHSA-PH9C-VWJQ-PQHJ

Affected Products

Cap-Go