Vulnerability Description
Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. Unauthenticated attackers can supply arbitrary user UUIDs to retrieve foreign users' organization membership, roles, management emails, and billing metadata.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Cap-go/capgo/security/advisories/GHSA-fch8-pp28-mw2x
- https://www.vulncheck.com/advisories/capgo-information-disclosure-via-get-orgs-v
- https://github.com/Cap-go/capgo/security/advisories/GHSA-fch8-pp28-mw2x
FAQ
What is CVE-2026-56279?
CVE-2026-56279 is a vulnerability with a CVSS score of 7.5 (HIGH). Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. Unauthenticated...
How severe is CVE-2026-56279?
CVE-2026-56279 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56279?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.