PT-2026-51154 · Cap Go · Cap-Go
Judel777
·
Published
2026-06-20
·
Updated
2026-06-20
·
CVE-2026-56295
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
An authorization bypass exists in webhook management endpoints. This issue allows non-expiring API keys to bypass the
require apikey expiration organization policy because the checkWebhookPermission() function fails to call apikeyHasOrgRightWithPolicy. Consequently, attackers using legacy non-expiring keys can list, create, and delete webhooks even when an organizational policy explicitly requires key expiration.Recommendations
Update to version 12.128.2 or later.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go