CVE-2026-56249
Last modified
CVE-2026-56249 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authenticated users to overwrite existing channels by reusing their names. Attackers with app.create_channel permission can exploit a logic mismatch between existence validation and upsert operations to reassign channel ownership and modify critical production channel configurations.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authenticated users to overwrite existing channels by reusing their names. Attackers with app.create_channel permission can exploit a logic mismatch between existence validation and upsert operations to reassign channel ownership and modify critical production channel configurations.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Capgo | Capgo | < 12.128.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-56249?
How severe is CVE-2026-56249?
How do I fix CVE-2026-56249?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-56243Capgo before 12.128.2 contains a security control bypass vul…8.6
- CVE-2026-56244Capgo before 12.128.2 allows non-admin API keys to read webh…7.1
- CVE-2026-56245Supabase Capgo before 12.128.2 contains an authorization byp…8.8
- CVE-2026-56246Capgo before 12.128.2 contains a broken access control vulne…8.1
- CVE-2026-56247Capgo before 12.128.2 allows org admins to assign org-scoped…8.8
- CVE-2026-56248Cap-go capgo (capgo-backend) before 12.128.12 contains an un…8.7
- CVE-2026-5625A weakness has been identified in assafelovic gpt-researcher…4.3
- CVE-2026-56250Capgo before 12.128.2 allows upload-scoped API keys to modif…8.7
- CVE-2026-56251Capgo before 12.128.2 contains a broken row level security p…7
- CVE-2026-56252Capgo before 12.128.2 contains a scope isolation vulnerabili…5.4
- CVE-2026-56253Capgo before 12.128.2 contains an improper access control vu…8.7
- CVE-2026-56254In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, …8.3
Are you affected by CVE-2026-56249?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
