Junglewise Threat Intelligence

CVE-2026-56322: Capgo information disclosure in unauthenticated updates endpoint

CVE-2026-56322 · Severity: high · CVSS 7.5 · Published 2026-06-23

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing over-the-air (OTA) updates for mobile applications, contains a security flaw in its update delivery system. An unauthorized person can use this flaw to discover private internal testing channels and view sensitive deployment details, such as app version numbers and platform configurations. This could allow competitors or malicious actors to monitor a company's internal development progress and release cycles.

Technical details

An information disclosure vulnerability exists in the Capgo /updates endpoint due to improper order of operations during request processing. The 'defaultChannel' parameter is resolved by name before privacy and self-assignment restrictions are enforced. An unauthenticated remote attacker can perform a side-channel attack by probing channel names; valid private channels return distinct error messages (e.g., platform-specific denials or version upgrade warnings) compared to nonexistent channels. This allows for the enumeration of private channel names and the extraction of sensitive metadata, including assigned bundle versions and platform-specific configuration states. The issue is fixed in version 12.128.2.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-05-07: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published and NVD record created

References

Related threats