PT-2026-51411 · Cap Go · Cap-Go
Judel777
·
Published
2026-06-22
·
Updated
2026-06-22
·
CVE-2026-56323
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel self endpoint that allows unauthenticated attackers to enumerate non-public channel names and determine app existence and subscription status. Remote attackers can send GET requests with arbitrary app id parameters to disclose internal rollout channels, enumerate valid applications across tenants, and leak billing status without authentication or device binding.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go