PT-2026-51221 · Cap Go · Cap-Go

Judel777

·

Publicado

2026-06-21

·

Atualizado

2026-06-21

·

CVE-2026-56242

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Capgo before 12.128.2 contains an unauthenticated security definer RPC function get identity apikey only that returns the owning user id for supplied API keys, creating an API key validity oracle and user identity disclosure primitive. Attackers can call this endpoint with valid or invalid API keys to confirm key validity and map keys to user identifiers, then chain results into other exposed RPCs like get orgs v6 to retrieve organization membership and management email PII.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-56242

Produtos afetados

Cap-Go