CVE-2026-56249

HIGH

Capgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /channel Name Collision

Title source: cna
STIX 2.1

Description

Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authenticated users to overwrite existing channels by reusing their names. Attackers with app.create_channel permission can exploit a logic mismatch between existence validation and upsert operations to reassign channel ownership and modify critical production channel configurations.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-vj24-j594-3wv3)
https://github.com/Cap-go/capgo/security/advisories/GHSA-vj24-j594-3wv3
Third Party Advisory third-party-advisory
VulnCheck Advisory: Capgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /channel Name Collision
https://www.vulncheck.com/advisories/capgo-unauthorized-channel-overwrite-and-ownership-takeover-via-post-channel-name-collision

Scores

CVSS v3 7.6
EPSS 0.0026
EPSS Percentile 17.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-285
Status published
Products (2)
Capgo/Capgo < 12.128.2
Capgo/Capgo 12.128.2
Published Jun 30, 2026
Tracked Since Jul 01, 2026