Vulnerability Description
Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity oracles and user UUID disclosure. Unauthenticated attackers using the public API key can validate leaked keys, enumerate users and apps, and determine permission levels, significantly increasing the actionability of compromised credentials.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Cap-go/capgo/security/advisories/GHSA-7r6g-whg3-5mm4
- https://www.vulncheck.com/advisories/capgo-unauthenticated-api-key-validity-and-
- https://github.com/Cap-go/capgo/security/advisories/GHSA-7r6g-whg3-5mm4
FAQ
What is CVE-2026-56300?
CVE-2026-56300 is a vulnerability with a CVSS score of 7.5 (HIGH). Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity oracles and user UUID disclosure. Unauthenticated att...
How severe is CVE-2026-56300?
CVE-2026-56300 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56300?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.