PT-2026-51157 · Cap Go · Cap-Go

Judel777

·

Published

2026-06-20

·

Updated

2026-06-20

·

CVE-2026-56319

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description An information disclosure issue exists in the 'GET /statistics/app/:app id' endpoint. This allows users with app-limited API keys to identify existing sibling app IDs by analyzing differential error responses. Specifically, attackers can enumerate valid app IDs outside their authorized scope by distinguishing between 500 PGRST116 errors, which occur for inaccessible apps, and 401 errors, which occur for nonexistent apps, thereby compromising tenant isolation.
Recommendations Update to version 12.128.2. Restrict access to the 'GET /statistics/app/:app id' endpoint or the app id parameter to minimize the risk of enumeration.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56319

Affected Products

Cap-Go