PT-2026-57553 · Cap Go · Cap-Go

·

CVE-2026-56281

·

Published

2026-07-12

·

Updated

2026-07-12

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description An issue exists in the 'POST /private/admin stats' endpoint where the limit parameter is extracted from an unvalidated request body and inserted directly into Cloudflare Analytics Engine SQL queries using template literals. An attacker with platform admin credentials can use this to inject SQL fragments, allowing them to enumerate dataset schemas, extract analytics data, or cause a denial-of-service against the analytics backend.
Recommendations Update to version 12.128.2 or later. Avoid using the limit parameter in the 'POST /private/admin stats' endpoint until the update is applied.

Exploit

Fix

DoS

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56281
GHSA-6FFX-8HJJ-JHHF

Affected Products

Cap-Go