CVE-2026-56255
Last modified
CVE-2026-56255 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticated users with org write permissions to create unlimited demo applications without rate limiting or quota enforcement. Attackers can repeatedly invoke this endpoint to generate approximately 138 database write operations per request, causing degraded performance, increased costs, and potential service instability.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticated users with org write permissions to create unlimited demo applications without rate limiting or quota enforcement. Attackers can repeatedly invoke this endpoint to generate approximately 138 database write operations per request, causing degraded performance, increased costs, and potential service instability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-56255?
How severe is CVE-2026-56255?
How do I fix CVE-2026-56255?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5625A weakness has been identified in assafelovic gpt-researcher…4.3
- CVE-2026-56250Capgo before 12.128.2 allows upload-scoped API keys to modif…8.7
- CVE-2026-56251Capgo before 12.128.2 contains a broken row level security p…7
- CVE-2026-56252Capgo before 12.128.2 contains a scope isolation vulnerabili…5.4
- CVE-2026-56253Capgo before 12.128.2 contains an improper access control vu…8.7
- CVE-2026-56254In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, …8.3
- CVE-2026-56256Capgo before 12.128.2 enforces mandatory two-factor authenti…7.1
- CVE-2026-56257Capgo before 12.128.2 allows direct patching of public.apps.…7.1
- CVE-2026-56258Crawl4AI before 0.8.8 contains an arbitrary file write vulne…9.2
- CVE-2026-56259Crawl4AI before 0.8.8 contains credential exfiltration vulne…8.8
- CVE-2026-5626The Survey Form Block plugin for WordPress is vulnerable to …4.3
- CVE-2026-56260Crawl4AI before 0.8.7 contains an arbitrary file write vulne…9.1
Are you affected by CVE-2026-56255?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
