CVE-2026-56279

HIGH

Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint

Title source: cna
STIX 2.1

Description

Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. Unauthenticated attackers can supply arbitrary user UUIDs to retrieve foreign users' organization membership, roles, management emails, and billing metadata.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-fch8-pp28-mw2x)
https://github.com/Cap-go/capgo/security/advisories/GHSA-fch8-pp28-mw2x
Third Party Advisory third-party-advisory
VulnCheck Advisory: Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint
https://www.vulncheck.com/advisories/capgo-information-disclosure-via-get-orgs-v7-rpc-endpoint

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 23.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
Capgo/Capgo < 12.128.2
Capgo/Capgo 12.128.2
Published Jul 10, 2026
Tracked Since Jul 10, 2026