PT-2026-51157 · Cap Go · Cap-Go
Judel777
·
Published
2026-06-20
·
Updated
2026-06-20
·
CVE-2026-56319
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
An information disclosure issue exists in the 'GET /statistics/app/:app id' endpoint. This allows users with app-limited API keys to identify existing sibling app IDs by analyzing differential error responses. Specifically, attackers can enumerate valid app IDs outside their authorized scope by distinguishing between 500 PGRST116 errors, which occur for inaccessible apps, and 401 errors, which occur for nonexistent apps, thereby compromising tenant isolation.
Recommendations
Update to version 12.128.2.
Restrict access to the 'GET /statistics/app/:app id' endpoint or the
app id parameter to minimize the risk of enumeration.Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go