CVE-2026-56229: Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/logs
Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that allows attackers to access build jobs belonging to different applications by supplying a mismatched appid and jobid combination. Limited API keys restricted to a single app can retrieve build status and logs from other apps by providing an authorized appid while using a jobid from an unauthorized app, exposing sensitive build information including logs, metadata, and potentially credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56229?
The severity of CVE-2026-56229 is rated as high, with a CVSS score of 7.1.
How do I fix CVE-2026-56229?
To fix CVE-2026-56229, upgrade Capgo to version 12.128.2 or later.
What type of vulnerability is CVE-2026-56229?
CVE-2026-56229 is an authorization bypass vulnerability.
What can attackers do with CVE-2026-56229?
Attackers can access build jobs belonging to different applications by exploiting the app_id and job_id mismatch.
Which software is affected by CVE-2026-56229?
CVE-2026-56229 affects Capgo versions before 12.128.2.