Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-56303: Capgo before 12.128.2 leaks sensitive API key information
CVE-2026-56303
Summary
An unauthenticated attacker can access sensitive information about API keys, including user details and key expiration, by exploiting a vulnerability in the Capgo API. This is a concern for organizations using Capgo, as it may compromise user data and security. To protect against this vulnerability, update to Capgo version 12.128.2 or later.
Original title
Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attac...
Original description
Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to retrieve sensitive API key metadata including user_id, mode, org scoping, and expiration details when supplied a valid key value.
nvd CVSS3.1
7.5
nvd CVSS4.0
8.7
Vulnerability type
CWE-200
Information Exposure
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026