Junglewise Threat Intelligence

CVE-2026-56323: Capgo information disclosure in channel_self endpoint

CVE-2026-56323 · Severity: high · CVSS 7.5 · Published 2026-06-22

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and deployments, contained a security flaw that allowed unauthorized individuals to view sensitive internal information. By sending specific requests to the service, an attacker could identify private development channels, confirm the existence of specific applications, and see the billing or subscription status of customers. This information could be used to plan more targeted attacks or gather competitive intelligence on Capgo users.

Technical details

An information disclosure vulnerability exists in Capgo's `/functions/v1/channel_self` endpoint due to a lack of authentication and authorization checks. The GET handler fails to call `checkPermission()` and does not require a `device_id` or API key, allowing any remote attacker to query the endpoint with arbitrary `app_id` parameters. This enables the enumeration of non-public internal rollout channels (e.g., dev, beta), confirmation of valid application IDs across different tenants, and the leakage of billing/subscription status through distinct error responses like 'need_plan_upgrade'. The issue was addressed in version 12.128.2 by implementing stricter access controls and normalizing responses.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-02-10: advisory: GitHub Security Advisory published
  • 2026-06-22: disclosed: CVE published and NVD record created

References

Related threats