PT-2026-51221 · Cap Go · Cap-Go
Judel777
·
Publicado
2026-06-21
·
Atualizado
2026-06-21
·
CVE-2026-56242
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Capgo before 12.128.2 contains an unauthenticated security definer RPC function get identity apikey only that returns the owning user id for supplied API keys, creating an API key validity oracle and user identity disclosure primitive. Attackers can call this endpoint with valid or invalid API keys to confirm key validity and map keys to user identifiers, then chain results into other exposed RPCs like get orgs v6 to retrieve organization membership and management email PII.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cap-Go