Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在授权问题漏洞,该漏洞源于未对GET /private/role_bindings/:org_id端点应用全局身份验证中间件,导致身份验证执行不一致,如果处理逻辑发生变化,可能造成授权绕过。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56324 | 8.2 HIGH | Capgo - Rate Limit Bypass via User-Controlled device_id Parameter |
| CVE-2026-56323 | 7.5 HIGH | Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self |
| CVE-2026-56314 | 7.1 HIGH | Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint |
| CVE-2026-56306 | 6.4 MEDIUM | Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing |
| CVE-2026-56311 | 5.3 MEDIUM | Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC |
| CVE-2026-56255 | 4.3 MEDIUM | Capgo - Denial of Service via Unlimited Demo App Creation |
No comments yet