CVE-2026-56252: Capgo - Scope Isolation Failure in Webhook Test Endpoint
Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations. Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary organization webhooks outside their declared app boundary, bypassing the limitedtoapps authorization check.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2026-56252?
CVE-2026-56252 is a medium-severity vulnerability in Capgo that allows app-scoped API keys to invoke organization-scoped webhook operations through a scope isolation failure.
What is the risk associated with CVE-2026-56252?
CVE-2026-56252 has a risk score of 34 and a CVSS severity rating of 5.3.
How do I fix CVE-2026-56252?
To fix CVE-2026-56252, update Capgo to version 12.128.2 or later.
Who is affected by CVE-2026-56252?
Users of Capgo versions prior to 12.128.2 are affected by CVE-2026-56252.
What type of vulnerability is CVE-2026-56252?
CVE-2026-56252 is classified as a scope isolation failure vulnerability in the webhook test endpoint.