CVE-2026-56242: Capgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_identity_apikey_only RPC
Capgo before 12.128.2 contains an unauthenticated security definer RPC function getidentityapikeyonly that returns the owning userid for supplied API keys, creating an API key validity oracle and user identity disclosure primitive. Attackers can call this endpoint with valid or invalid API keys to confirm key validity and map keys to user identifiers, then chain results into other exposed RPCs like getorgsv6 to retrieve organization membership and management email PII.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56242?
CVE-2026-56242 has a high severity rating of 7.5.
How do I fix CVE-2026-56242?
To fix CVE-2026-56242, update to a patched version of Capgo released after 12.128.2.
What type of vulnerability is CVE-2026-56242?
CVE-2026-56242 is categorized as an information leak vulnerability.
What can an attacker do with CVE-2026-56242?
An attacker can exploit CVE-2026-56242 to determine the validity of API keys and disclose the user identity associated with them.
Which software is affected by CVE-2026-56242?
CVE-2026-56242 affects the Capgo software before version 12.128.2.