PT-2026-51223 · Cap Go · Cap-Go

Judel777

·

Publicado

2026-06-21

·

Atualizado

2026-06-21

·

CVE-2026-56253

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Capgo before 12.128.2 contains an improper access control vulnerability in the public.get org members RPC function that allows unauthenticated attackers to enumerate organization members. Attackers can invoke the endpoint using only the public sb publishable * key and an organization UUID to retrieve sensitive member information including email addresses, user IDs, roles, and pending invitations.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-56253

Produtos afetados

Cap-Go