Junglewise Threat Intelligence

CVE-2026-56318: Capgo information disclosure in validate_password_compliance endpoint

CVE-2026-56318 · Severity: medium · CVSS 5.3 · Published 2026-06-30

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and backend services, contained a flaw that allowed outsiders to verify if specific organizations use the service. By sending specially crafted requests to a password validation tool, an attacker could distinguish between valid and invalid organization IDs based on the server's error messages. While this does not grant direct access to private data, it allows for the mapping of Capgo's customer base.

Technical details

An information disclosure vulnerability exists in the `/private/validate_password_compliance` endpoint of Capgo due to inconsistent error handling. The endpoint acts as an 'existence oracle' by returning distinct responses for different input states: a 400 error for malformed UUIDs, a 404 'org_not_found' error for non-existent UUIDs, and a specific 'no_policy' error for valid, existing organization UUIDs. An unauthenticated remote attacker can exploit this behavior to confirm the existence of specific organization IDs. While UUIDs are difficult to brute-force, this allows for targeted verification of known or leaked IDs. The issue is resolved in version 12.128.2 by normalizing error responses.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-02-25: advisory: GitHub Security Advisory published
  • 2026-06-30: disclosed: NVD publication date

References

Related threats