Junglewise Threat Intelligence

CVE-2026-69113: Cap broken access control in video comment endpoint

CVE-2026-69113 · Severity: medium · CVSS 5.4 · Published 2026-08-11

Executive brief

Cap is an open-source screen recording application similar to Loom. An authenticated user can post comments on private videos belonging to other users by manipulating the request, potentially embarrassing video owners and triggering unwanted notifications. This breaks the confidentiality of private recordings.

Technical details

The vulnerability is a broken access control (IDOR) flaw in the POST /api/video/comment endpoint. An authenticated user can post comments on private videos by supplying an arbitrary videoId in the request body, bypassing authorization checks that should verify the user has access to view the target video. The attack requires authentication but no additional user interaction. Attackers can inject arbitrary comments, trigger comment notification emails to video owners, and enumerate valid video IDs by analyzing response differences. A patch was released in commit 1b812d8 requiring canView access verification before allowing comment submission.

Affected products

  • CapSoftware Cap v0.3.1

Timeline

  • 2026-08-11: disclosed
  • 2026: patched: Fix released in commit 1b812d8

References

Related threats