Vulnerability Description
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO provider identifiers, enabling reconnaissance against Capgo tenants.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Cap-go/capgo/security/advisories/GHSA-c5jf-5wxg-mgrq
- https://www.vulncheck.com/advisories/capgo-information-disclosure-via-unauthenti
- https://github.com/Cap-go/capgo/security/advisories/GHSA-c5jf-5wxg-mgrq
FAQ
What is CVE-2026-56336?
CVE-2026-56336 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enum...
How severe is CVE-2026-56336?
CVE-2026-56336 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56336?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.