CVE-2026-56303: Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function
Capgo before 12.128.2 contains an information disclosure vulnerability in the findapikeybyvalue PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/findapikeybyvalue endpoint to retrieve sensitive API key metadata including userid, mode, org scoping, and expiration details when supplied a valid key value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56303?
CVE-2026-56303 has a severity score of 8.7, classified as high.
How do I fix CVE-2026-56303?
To fix CVE-2026-56303, upgrade Capgo to version 12.128.2 or later.
What type of vulnerability is CVE-2026-56303?
CVE-2026-56303 is an information leakage vulnerability affecting API key metadata.
Who can exploit CVE-2026-56303?
CVE-2026-56303 can be exploited by unauthenticated attackers.
What is the impact of CVE-2026-56303?
CVE-2026-56303 allows attackers to retrieve sensitive API key metadata without authentication.